Malicious code in mcp-server-pg (npm)
The mcp-server-pg npm package contains malicious code that, upon installation, collects extensive personal and organizational data from the developer's environment and sends it to a hardcoded external endpoint without clear disclosure. This data includes OS hostname, usernames, Git configuration, SSH public key comments, cloud service account details, and DNS resolver settings. The telemetry is opt-out rather than opt-in and activates automatically during installation. The collected information can be used to fingerprint developers and correlate identities across multiple services, enabling targeted follow-on attacks. Removal of the package does not guarantee elimination of all resulting malicious software, and any system with this package installed should be considered fully compromised.
AI Analysis
Technical Summary
The mcp-server-pg npm package versions listed contain a post-install script that unconditionally harvests sensitive identity and configuration files from the host environment and transmits them as JSON to a hardcoded external URL. The data collected includes OS and user identifiers, Git repository metadata, SSH public key comments, GitHub and cloud service configuration files, and DNS settings. Although the script claims to collect 'anonymous diagnostics' and no credentials, the actual data enables precise developer fingerprinting and correlation of identities across source control and cloud platforms. The telemetry is enabled by default with an opt-out environment variable, and there is no README disclosure of this behavior. According to the source, any system with this package installed should be treated as fully compromised, requiring immediate secret and key rotation from a clean system. No official patch or remediation is indicated in the data provided.
Potential Impact
The malicious post-install script exfiltrates sensitive personal and organizational information that can be used to identify and track developers across multiple platforms. This exposure increases the risk of targeted attacks, including credential theft and unauthorized access to cloud and source control accounts. The compromise is severe enough that affected systems should be considered fully compromised, with all stored secrets and keys rotated immediately. Removal of the package alone may not eliminate all malicious components introduced by the package.
Mitigation Recommendations
No official patch or fix is currently documented. Immediate removal of the mcp-server-pg package is recommended. Treat any system with this package installed as fully compromised and perform comprehensive secret and key rotation from a separate, trusted system. Disable the telemetry by setting the MCP_SERVER_PG_TELEMETRY_DISABLE environment variable to opt out of data collection if the package must be used temporarily, though this does not mitigate the risk from prior installations. Monitor for any unusual activity and consider rebuilding affected systems to ensure complete remediation.
Malicious code in mcp-server-pg (npm)
Description
The mcp-server-pg npm package contains malicious code that, upon installation, collects extensive personal and organizational data from the developer's environment and sends it to a hardcoded external endpoint without clear disclosure. This data includes OS hostname, usernames, Git configuration, SSH public key comments, cloud service account details, and DNS resolver settings. The telemetry is opt-out rather than opt-in and activates automatically during installation. The collected information can be used to fingerprint developers and correlate identities across multiple services, enabling targeted follow-on attacks. Removal of the package does not guarantee elimination of all resulting malicious software, and any system with this package installed should be considered fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The mcp-server-pg npm package versions listed contain a post-install script that unconditionally harvests sensitive identity and configuration files from the host environment and transmits them as JSON to a hardcoded external URL. The data collected includes OS and user identifiers, Git repository metadata, SSH public key comments, GitHub and cloud service configuration files, and DNS settings. Although the script claims to collect 'anonymous diagnostics' and no credentials, the actual data enables precise developer fingerprinting and correlation of identities across source control and cloud platforms. The telemetry is enabled by default with an opt-out environment variable, and there is no README disclosure of this behavior. According to the source, any system with this package installed should be treated as fully compromised, requiring immediate secret and key rotation from a clean system. No official patch or remediation is indicated in the data provided.
Potential Impact
The malicious post-install script exfiltrates sensitive personal and organizational information that can be used to identify and track developers across multiple platforms. This exposure increases the risk of targeted attacks, including credential theft and unauthorized access to cloud and source control accounts. The compromise is severe enough that affected systems should be considered fully compromised, with all stored secrets and keys rotated immediately. Removal of the package alone may not eliminate all malicious components introduced by the package.
Mitigation Recommendations
No official patch or fix is currently documented. Immediate removal of the mcp-server-pg package is recommended. Treat any system with this package installed as fully compromised and perform comprehensive secret and key rotation from a separate, trusted system. Disable the telemetry by setting the MCP_SERVER_PG_TELEMETRY_DISABLE environment variable to opt out of data collection if the package must be used temporarily, though this does not mitigate the risk from prior installations. Monitor for any unusual activity and consider rebuilding affected systems to ensure complete remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6922
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-cfv7-74pc-vmff"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a50ba9768715ace43582595
Added to database: 07/10/2026, 09:25:43 UTC
Last enriched: 07/10/2026, 10:09:59 UTC
Last updated: 07/30/2026, 02:39:52 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.