Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in mcp-server-pg (npm)

0
Critical
Published: 07/07/2026 (07/07/2026, 13:59:38 UTC)
Source: GCVE Database
Product: mcp-server-pg

Description

The mcp-server-pg npm package contains malicious code that, upon installation, collects extensive personal and organizational data from the developer's environment and sends it to a hardcoded external endpoint without clear disclosure. This data includes OS hostname, usernames, Git configuration, SSH public key comments, cloud service account details, and DNS resolver settings. The telemetry is opt-out rather than opt-in and activates automatically during installation. The collected information can be used to fingerprint developers and correlate identities across multiple services, enabling targeted follow-on attacks. Removal of the package does not guarantee elimination of all resulting malicious software, and any system with this package installed should be considered fully compromised.

Affected software

npmghsa
mcp-server-pg
Affected versions
=1.2.1=1.1.0=1.2.2=1.1.1=0.7.0=0.1.0=0.2.1=0.2.0=0.6.0=0.8.0=0.3.1=0.9.0=0.3.0=0.1.1=0.4.0=0.1.3=0.5.0=1.0.1=0.1.2=1.2.0=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/10/2026, 10:09:59 UTC

Technical Analysis

The mcp-server-pg npm package versions listed contain a post-install script that unconditionally harvests sensitive identity and configuration files from the host environment and transmits them as JSON to a hardcoded external URL. The data collected includes OS and user identifiers, Git repository metadata, SSH public key comments, GitHub and cloud service configuration files, and DNS settings. Although the script claims to collect 'anonymous diagnostics' and no credentials, the actual data enables precise developer fingerprinting and correlation of identities across source control and cloud platforms. The telemetry is enabled by default with an opt-out environment variable, and there is no README disclosure of this behavior. According to the source, any system with this package installed should be treated as fully compromised, requiring immediate secret and key rotation from a clean system. No official patch or remediation is indicated in the data provided.

Potential Impact

The malicious post-install script exfiltrates sensitive personal and organizational information that can be used to identify and track developers across multiple platforms. This exposure increases the risk of targeted attacks, including credential theft and unauthorized access to cloud and source control accounts. The compromise is severe enough that affected systems should be considered fully compromised, with all stored secrets and keys rotated immediately. Removal of the package alone may not eliminate all malicious components introduced by the package.

Mitigation Recommendations

No official patch or fix is currently documented. Immediate removal of the mcp-server-pg package is recommended. Treat any system with this package installed as fully compromised and perform comprehensive secret and key rotation from a separate, trusted system. Disable the telemetry by setting the MCP_SERVER_PG_TELEMETRY_DISABLE environment variable to opt out of data collection if the package must be used temporarily, though this does not mitigate the risk from prior installations. Monitor for any unusual activity and consider rebuilding affected systems to ensure complete remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6922
Osv Schema Version
1.7.4
Aliases
["GHSA-cfv7-74pc-vmff"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a50ba9768715ace43582595

Added to database: 07/10/2026, 09:25:43 UTC

Last enriched: 07/10/2026, 10:09:59 UTC

Last updated: 07/30/2026, 02:39:52 UTC

Views: 21

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses