TL;DR While building a public advisory database for the Model Context Protocol (MCP) ecosystem, we unpacked and read the shipped code of 30+ npm packages flagged as malicious in public feeds (OSV/GHSA) in the AI-agent space — the discoveries are those feeds' work, the tarball-level verification below is ours. We verified 19 of them as malicious in... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
18 malicious npm packages are still remote-controlling AI coding agents (verified today)
TL;DR While building a public advisory database for the Model Context Protocol (MCP) ecosystem, we unpacked and read the shipped code of 30+ npm packages flagged as malicious in public feeds (OSV/GHSA) in the AI-agent space — the d…
Reagiere als Erste:r — dein Feedback zählt!