pypi · Malicious package advisory
Malwareant-mcp-proxy-for-test
MAL-2026-2669
Malicious code in ant-mcp-proxy-for-test (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (51df3beb4457da4a841727c91a2517ba5727c841c08f9d43cf2b25be9e476564) During use of the package, it silently downloads and executes remote executables or scripts. During analysis, the remote resources were no longer available. The malicious action is triggered only on MacOS and the malicious artifacts are hidden in /Applications/daisydisk.app --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-ant-mcp-proxy-for-test Reasons (based on the campaign): - Downloads and executes a remote executable. - action-hidden-in-lib-usage
Compromised versions (1)
- 0.10.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.