xrblocks-mcp @6.3.1
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC
OSV ID
MAL-2026-13988
Ecosystem
npm
Summary
The package's postinstall lifecycle script runs automatically on npm install and collects installer host identifiers (hostname, platform, arch, node version, package name, timestamp) and POSTs them to the hardcoded endpoint https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp. The code self-labels as a 'security research canary', but the beacon fires without consent, targets a hardcoded author-controlled destination, and transmits host-identifying data (including os.hostname()) that has no bearing on the package's declared functionality.
Source: amazon-inspector (76393473878ee61f371bcb238c278a7ae68f2a802d5a8b017d72812ab61c3c09)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.