Malicious code in mcp-search-server (PyPI)
mcp-search-server on PyPI contained malicious code in versions published from July 2026 onward. The package included hidden "phone home" functionality disguised as a "share compute swarm" feature, and was part of a coordinated campaign with another malicious package designed to deploy coin miners on user machines.
- Disclosed
- Last updated
- Blast radius
- All users who installed mcp-search-server versions published since 2026-07
- Ecosystems
- Attack vectors
- Affected entities
- mcp-search-server · 2026-07 and laterPyPI package with malicious code
The PyPI package mcp-search-server was found to contain malicious code in versions released from July 2026 onwards. The malicious functionality was disguised as a "share compute swarm" feature advertised for "faster results," but the implementation only performed reconnaissance by reporting home on every run.
The package was published by user kam193 as part of a coordinated malicious campaign. A companion package published simultaneously by the same user advertised AI boosting capabilities but actually initiated cryptocurrency mining. The wording and implementation of the "swarm" functionality evolved across releases, initially presented as an optional feature but later silently forced into the code as mandatory phone-home behavior.
Based on the coordinated nature of the campaign and the companion coin-mining package, security researchers assessed that mcp-search-server was preparing infrastructure to deploy coin miners on affected user machines. The campaign has been classified as clearly malicious with intent similar to infostealers.
The incident was identified and credited to the OpenSSF malicious packages project.
Indicators of compromise
- Packages
- mcp-search-server
Remediation
- Immediately uninstall mcp-search-server from all systems
- Audit systems that had mcp-search-server installed for signs of unauthorized processes, network connections, or cryptocurrency mining activity
- Review process logs and network traffic from the period when the package was installed
- Consider the affected system potentially compromised and monitor for further malicious activity
- Do not reinstall mcp-search-server; identify and use legitimate alternatives for the intended functionality
Sources
- GitHub Advisory GHSA-3rhm-6v7p-whrg · GitHub Advisory Database
Cite this entry
"Malicious code in mcp-search-server (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 30, 2026; last updated July 30, 2026. https://supplychainattack.org/incident/malicious-code-in-mcp-search-server-pypi-14rc34
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package
The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.
TeamPCPPyPICompromised packageMalicious maintainer - containedhigh
lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel
The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.
Mini Shai HuludPyPICompromised packageMalicious maintainer - resolvedhigh
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon attributed multiple high-profile npm supply chain attacks targeting the Debug and Chalk packages to North Korean threat actors. The incidents involved compromised packages in the npm ecosystem with significant downstream impact.
Lazarus GroupnpmCompromised packageMalicious maintainer