OpenSSF/OSV advisory MAL-2026-14230 confirms this npm version as malicious. chrome-enterprise-premium-mcp ships a postinstall lifecycle script that fires automatically on `npm install` and POSTs installer host metadata (os.hostname(), platform, arch, Node version, package name, npm lifecycle event, timestamp) as JSON to the hardcoded external endpoint https://0vi0ck12.instances.poc.jchunt.top/chrome-enterprise-premium-mcp...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in chrome-enterprise-premium-mcp (npm)
Details
chrome-enterprise-premium-mcp ships a postinstall lifecycle script that fires automatically on `npm install` and POSTs installer host metadata (os.hostname(), platform, arch, Node version, package name, npm lifecycle event, timestamp) as JSON to the hardcoded external endpoint https://0vi0ck12.instances.poc.jchunt.top/chrome-enterprise-premium-mcp. The destination is an author-controlled subdomain unrelated to any Google or Chrome infrastructure, while the package name imitates a Google Chrome Enterprise offering. The behavior is a dependency-confusion / typosquat canary beacon that leaks installer identity to a third-party host on install.
Decision reason
OpenSSF Malicious Packages via OSV confirms chrome-enterprise-premium-mcp@1.0.0 as malicious (MAL-2026-14230): Malicious code in chrome-enterprise-premium-mcp (npm)