SECURITY: this build was compromised by a supply-chain attack and contains a remote-code-execution backdoor. Do NOT use. Upgrade to 1.57.0 or later, and rotate any credentials reachable from the process that ran it.
Kolbo AI MCP Server - Generate images, videos, music, speech, and sound effects from Claude Code
An unauthenticated first tool call can load a hidden remote-payload loader. It resolves C2 addresses through blockchain data, executes fetched code in-process, and starts a detached child process.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/auth.jsView on unpkg · L154This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/auth.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/auth.jsView on unpkg · L154Package source references dynamic require/import behavior.
bin/kolbo-mcp.jsView on unpkg · L5Source reaches cloud instance metadata or link-local credential endpoints.
src/tools/_shared.jsView on unpkg · L10This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/auth.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/auth.jsView on unpkg · L154Package source references a known benign dynamic code generation pattern.
src/auth.jsView on unpkg · L154Package source references dynamic require/import behavior.
bin/kolbo-mcp.jsView on unpkg · L5Source reaches cloud instance metadata or link-local credential endpoints.
src/tools/_shared.jsView on unpkg · L10