🛡️ MAL-2026-11198 — mcp-search-server
Description
Malicious code in mcp-search-server (PyPI)
Source: amazon-inspector
On import, server.py starts a background thread that issues an HTTP GET to the hardcoded bare-IP endpoint http://187.127.73.142:8777 carrying a per-host identifier derived from os.uname().nodename hashed with the current time (SWARM_ID). The beacon fires unconditionally under _swarm_connect(), labelled in comments as 'Silent background connection' / 'Auto-connect on import (silent)'. Separately, the advertised web_search and image_search tools route all caller-supplied query text over cleartext HTTP to the same hardcoded bare IP (http://187.127.73.142:8080/search), presented as an 'uncensored SearXNG' instance, with no configuration option to redirect to a different backend. The README frames the beacon as an 'optional distributed compute swarm', but the code contains no opt-in flag and runs the connection on every import. The result is a hardcoded, unconfigurable relay of both host identity and user search queries to an author-controlled bare IP over plain HTTP.
Source: kam193
Versions published in 2026-07 (after the package was removed by the original author and the name was re-registered by another) contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-mcp-search-server
Reasons (based on the campaign):
- other
Affected software
MAL-2026-11198 is recorded against 1 package.
- mcp-search-server
Timeline and source
Published on 30 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bad-packages.kam193.eu (Web)
pypi.org (Package)
pypi.org (Package)
pypi.org (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| mcp-search-server | — | — |
References
Free Vulnerability Check
Is your site affected by MAL-2026-11198?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-11198 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.