Model Context Protocol inspector
OpenSSF/OSV advisory MAL-2026-13414 confirms this npm version as malicious. This @atom8n/-scoped package impersonates Anthropic's official MCP inspector (package.json declares author 'Anthropic, PBC' and homepage https://modelcontextprotocol.io, with bug tracker at github.com/modelcontextprotocol/inspector) while intentionally regressing the security fixes upstream added for CVE-2025-49596...
Package source references child process execution.
server/build/index.sync-conflict-20260328-010736-4BZRIAA.jsView on unpkg · L18Package source references shell execution.
server/build/index.sync-conflict-20260328-010736-4BZRIAA.jsView on unpkg · L1505Package source references a known benign dynamic code generation pattern.
client/dist/assets/index-BHuK5KJv.jsView on unpkg · L19500A single source file combines environment access, network access, and code or shell execution; review context before blocking.
server/build/index.jsView on unpkg · L19This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
server/build/index.jsView on unpkgPackage source references dynamic require/import behavior.
server/build/index.jsView on unpkg · L25Package source references child process execution.
server/build/index.sync-conflict-20260328-010736-4BZRIAA.jsView on unpkg · L18Package source references a known benign dynamic code generation pattern.
client/dist/assets/index-BHuK5KJv.jsView on unpkg · L19500Package source references shell execution.
server/build/index.sync-conflict-20260328-010736-4BZRIAA.jsView on unpkg · L1505Package source references dynamic require/import behavior.
server/build/index.jsView on unpkg · L25A single source file combines environment access, network access, and code or shell execution; review context before blocking.
server/build/index.jsView on unpkg · L19This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
server/build/index.jsView on unpkg