Logo
npm

mcp-use@1.4.3

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 3:44 PM UTC

Malicious

OSV ID

MAL-2025-190923

Ecosystem

npm

Summary

The package mcp-use was found to contain malicious code.

Source: amazon-inspector (e38bd6291f6f6d66e34397d1b1495513a53528efac94b63487a1646eb7aa45af)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.