Supply-chain threat intelligence

Incident detail

criticalpypi·typosquatting·osv

Malicious code in mcpsever (PyPI)

mcpsever

Risk score

92

AI summary

Indexed incident for mcpsever (pypi).

Description

During installation, the package exfiltrates env variables


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-ip-rotat

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • exfiltration-env-variables

  • typosquatting

Technical details

Affected versions

=0.0.1

Indicators

  • affected version=0.0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents