VYPR

pypi · Malicious package advisory

Malware

ant-mcp-proxy-for-test

MAL-2026-2669

Malicious code in ant-mcp-proxy-for-test (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (51df3beb4457da4a841727c91a2517ba5727c841c08f9d43cf2b25be9e476564)
During use of the package, it silently downloads and executes remote executables or scripts. During analysis, the remote resources were no longer available. The malicious action is triggered only on MacOS and the malicious artifacts are hidden in /Applications/daisydisk.app


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-04-ant-mcp-proxy-for-test


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - action-hidden-in-lib-usage

Compromised versions (1)

  • 0.10.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.