Malicious code in sidecar-mcp (npm)
The npm package sidecar-mcp contains malicious code that silently adds a hardcoded SSH public key to the user's authorized_keys file and enables Remote Login on macOS. This creates a persistent backdoor allowing unauthorized SSH access to the affected machine. The package does not disclose these actions, and the backdoor persists even after the package is removed. The intended functionality of the package does not require these changes, indicating deliberate malicious behavior.
AI Analysis
Technical Summary
The sidecar-mcp npm package installs a CLI tool that, when run, appends a hardcoded ed25519 public key to the current user's ~/.ssh/authorized_keys file with secure permissions and enables the macOS SSH daemon via system settings and launchctl. This grants persistent inbound SSH access to the machine for anyone possessing the corresponding private key. These actions are not disclosed to the user and are unrelated to the advertised purpose of setting up Sidecar MCP servers. The backdoor remains active even if the package is uninstalled, compromising the system's security.
Potential Impact
Any system with this package installed and executed is fully compromised, as unauthorized remote SSH access is established without user consent. Attackers can gain persistent interactive shell access, potentially leading to full system control. All secrets and keys stored on the compromised machine should be considered exposed and rotated immediately. Removing the package alone does not guarantee removal of all malicious components or access.
Mitigation Recommendations
Remove the sidecar-mcp package immediately. Rotate all secrets, SSH keys, and credentials that were stored or used on the compromised machine from a secure, separate device. Inspect the system for additional persistence mechanisms or malware, as the backdoor survives package removal. There is no official patch or fix available; remediation requires manual removal and credential rotation.
Malicious code in sidecar-mcp (npm)
Description
The npm package sidecar-mcp contains malicious code that silently adds a hardcoded SSH public key to the user's authorized_keys file and enables Remote Login on macOS. This creates a persistent backdoor allowing unauthorized SSH access to the affected machine. The package does not disclose these actions, and the backdoor persists even after the package is removed. The intended functionality of the package does not require these changes, indicating deliberate malicious behavior.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sidecar-mcp npm package installs a CLI tool that, when run, appends a hardcoded ed25519 public key to the current user's ~/.ssh/authorized_keys file with secure permissions and enables the macOS SSH daemon via system settings and launchctl. This grants persistent inbound SSH access to the machine for anyone possessing the corresponding private key. These actions are not disclosed to the user and are unrelated to the advertised purpose of setting up Sidecar MCP servers. The backdoor remains active even if the package is uninstalled, compromising the system's security.
Potential Impact
Any system with this package installed and executed is fully compromised, as unauthorized remote SSH access is established without user consent. Attackers can gain persistent interactive shell access, potentially leading to full system control. All secrets and keys stored on the compromised machine should be considered exposed and rotated immediately. Removing the package alone does not guarantee removal of all malicious components or access.
Mitigation Recommendations
Remove the sidecar-mcp package immediately. Rotate all secrets, SSH keys, and credentials that were stored or used on the compromised machine from a secure, separate device. Inspect the system for additional persistence mechanisms or malware, as the backdoor survives package removal. There is no official patch or fix available; remediation requires manual removal and credential rotation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10161
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a520ecc68715ace438f63f5
Added to database: 07/11/2026, 09:37:16 UTC
Last enriched: 09/12/2026, 18:47:36 UTC
Last updated: 09/12/2026, 18:47:36 UTC
Views: 45
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.