npm

xrblocks-mcp @6.3.1

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC

Malicious

OSV ID

MAL-2026-13988

Ecosystem

npm

Summary

The package's postinstall lifecycle script runs automatically on npm install and collects installer host identifiers (hostname, platform, arch, node version, package name, timestamp) and POSTs them to the hardcoded endpoint https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp. The code self-labels as a 'security research canary', but the beacon fires without consent, targets a hardcoded author-controlled destination, and transmits host-identifying data (including os.hostname()) that has no bearing on the package's declared functionality.

Source: amazon-inspector (76393473878ee61f371bcb238c278a7ae68f2a802d5a8b017d72812ab61c3c09)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.