broadcast-graphics-mcp @1.0.0
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC
OSV ID
MAL-2026-14228
Ecosystem
npm
Summary
The package's postinstall script runs automatically on npm install and collects host identifiers from the installer machine (os.hostname(), platform, arch, node version, package name, npm lifecycle event, timestamp), then POSTs them as JSON to the hardcoded host 2obx43du.instances.poc.jchunt.top at path /broadcast-graphics-mcp . The destination is not a first-party or user-configurable endpoint; installation of the package unconditionally leaks installer-side identity data to a remote party. The package self-labels as a 'security research canary', but self-labeling does not change the behavior: installing this package causes install-time exfiltration of host metadata to an author-controlled endpoint.
Source: amazon-inspector (48987a1a0ccff7dce1134e1a98122cd902961ac34ba623ae0e2fef62f75fe213)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.