npm

broadcast-graphics-mcp @1.0.0

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC

Malicious

OSV ID

MAL-2026-14228

Ecosystem

npm

Summary

The package's postinstall script runs automatically on npm install and collects host identifiers from the installer machine (os.hostname(), platform, arch, node version, package name, npm lifecycle event, timestamp), then POSTs them as JSON to the hardcoded host 2obx43du.instances.poc.jchunt.top at path /broadcast-graphics-mcp . The destination is not a first-party or user-configurable endpoint; installation of the package unconditionally leaks installer-side identity data to a remote party. The package self-labels as a 'security research canary', but self-labeling does not change the behavior: installing this package causes install-time exfiltration of host metadata to an author-controlled endpoint.

Source: amazon-inspector (48987a1a0ccff7dce1134e1a98122cd902961ac34ba623ae0e2fef62f75fe213)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.