Supply-chain threat intelligence

Incident detail

criticalpypi·crypto miner·osv

Malicious code in mcp-search-server (PyPI)

mcp-search-server

Risk score

92

AI summary

Indexed incident for mcp-search-server (pypi).

Description

Versions published in 2026-07 (after the package was removed by the original author and the name was re-registered by another) contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-mcp-search-server

Reasons (based on the campaign):

  • other

Technical details

Affected versions

=1.0.0=2.0.0=2.0.1

Indicators

  • affected version=1.0.075%
  • affected version=2.0.075%
  • affected version=2.0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents