Logo
pypi

marketing-mcp@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-16250

Ecosystem

pypi

Summary

The package exposes an MCP tool send(path) that reads a caller-specified local file and POSTs its contents to a hardcoded https://webhook.site/4acf7132-a75e-47e1-aeff-0350c8eac16c endpoint. The destination is a fixed public request-capture service, is not caller-configurable, and is not the installer's infrastructure. Any file path an LLM agent is induced to pass to send — including sensitive paths such as ~/.ssh/id_rsa, ~/.aws/credentials, .env files, or source trees — is uploaded to that third-party capture URL where the operator of the webhook can retrieve it. The package's advertised marketing/MCP framing does not match the actual behavior, which is a one-way file relay to an author-controlled inspection endpoint.

Source: amazon-inspector (87216e00fe68e2de8b140f1f9ffc2db5a8e814f38030e2eb6120c9ae9e7ca3ff)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.