Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in xrblocks-mcp (npm)

The npm package xrblocks-mcp contained malicious code in its postinstall lifecycle script that automatically executed on installation, collecting and exfiltrating host identifiers to an attacker-controlled endpoint without user consent.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All npm users who installed xrblocks-mcp
Ecosystems
Attack vectors
Affected entities
  • xrblocks-mcpnpm package containing malicious postinstall script

The npm package xrblocks-mcp was found to contain malicious code embedded in its postinstall lifecycle script. This script executed automatically whenever the package was installed via npm install, without requiring explicit user action or consent.

The malicious script collected sensitive host-identifying information including hostname, platform, architecture, Node.js version, package name, and timestamp. This data was then transmitted via HTTP POST to a hardcoded attacker-controlled endpoint at https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp.

Although the code self-labeled as a 'security research canary', the beacon transmission was unconditional and targeted a hardcoded author-controlled destination. The collected data (particularly os.hostname()) had no legitimate connection to the package's declared functionality, indicating intentional data exfiltration.

The incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious npm packages.

Indicators of compromise

Packages
  • xrblocks-mcp
Domains
  • 6cjhdzmo.instances.poc.jchunt.top

Remediation

  • Remove xrblocks-mcp from all environments immediately
  • Audit npm install logs to identify systems that installed this package
  • Review network logs for connections to 6cjhdzmo.instances.poc.jchunt.top
  • Consider hostname and system information potentially exposed as compromised
  • Update npm dependencies to remove any references to xrblocks-mcp
  • Monitor affected systems for further suspicious activity

Sources

  1. GitHub Advisory GHSA-pwwg-f86j-hmv7 · GitHub Advisory Database

Cite this entry

"Malicious code in xrblocks-mcp (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 13, 2026; last updated August 13, 2026. https://supplychainattack.org/incident/malicious-code-in-xrblocks-mcp-npm-szp1by

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in checkout-desktop-total (npm)

    The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.

    npmCompromised package
  2. resolvedcritical

    Malicious code in epic-common-node (npm)

    The npm package epic-common-node was found to contain malicious code. The package has been identified and reported through GitHub Security Advisory GHSA-m36g-mhjr-ww2c.

    npmCompromised package
  3. containedcritical

    Malicious code in epic-common (npm)

    The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.

    npmCompromised package
  4. containedcritical

    Malicious code in pfp-forms-sme-loan (npm)

    The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.

    npmCompromised packageMalicious commit