THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalnpm·malware·osv

Malicious code in mcp-server-supabase (npm)

mcp-server-supabase

Risk score

92

AI summary

Indexed incident for mcp-server-supabase (npm).

Description

Package name impersonates the official scoped Supabase MCP server. package.json declares "postinstall": "node index.js", which fires automatically on npm install and unconditionally POSTs installer metadata — os.hostname(), process.cwd(), process.env.npm_config_user_agent, Node version, and os.platform() — to a hardcoded Cloudflare Workers endpoint at https://npx-canary-log.vulnerable-live.workers.dev/log. The package ships no functionality consumers requested; its entire on-install effect is the outbound beacon. Installers resolved to this unscoped name get their hostname and working-directory path silently transmitted to third-party infrastructure without consent.

Technical details

Affected versions

=0.0.1

Indicators

  • affected version=0.0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents