Malicious code in xrblocks-mcp (npm)
The npm package xrblocks-mcp contained malicious code in its postinstall lifecycle script that automatically executed on installation, collecting and exfiltrating host identifiers to an attacker-controlled endpoint without user consent.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed xrblocks-mcp
- Ecosystems
- Attack vectors
- Affected entities
- xrblocks-mcpnpm package containing malicious postinstall script
The npm package xrblocks-mcp was found to contain malicious code embedded in its postinstall lifecycle script. This script executed automatically whenever the package was installed via npm install, without requiring explicit user action or consent.
The malicious script collected sensitive host-identifying information including hostname, platform, architecture, Node.js version, package name, and timestamp. This data was then transmitted via HTTP POST to a hardcoded attacker-controlled endpoint at https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp.
Although the code self-labeled as a 'security research canary', the beacon transmission was unconditional and targeted a hardcoded author-controlled destination. The collected data (particularly os.hostname()) had no legitimate connection to the package's declared functionality, indicating intentional data exfiltration.
The incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious npm packages.
Indicators of compromise
- Packages
- xrblocks-mcp
- Domains
- 6cjhdzmo.instances.poc.jchunt.top
Remediation
- Remove xrblocks-mcp from all environments immediately
- Audit npm install logs to identify systems that installed this package
- Review network logs for connections to 6cjhdzmo.instances.poc.jchunt.top
- Consider hostname and system information potentially exposed as compromised
- Update npm dependencies to remove any references to xrblocks-mcp
- Monitor affected systems for further suspicious activity
Sources
- GitHub Advisory GHSA-pwwg-f86j-hmv7 · GitHub Advisory Database
Cite this entry
"Malicious code in xrblocks-mcp (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-xrblocks-mcp-npm-szp1by
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - resolvedcritical
Malicious code in epic-common-node (npm)
The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.
npmCompromised package - containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit