Malicious code in mcp-server-supabase (npm)
-= Per source details. Do not edit below this line.=-
Package squats the unscoped name mcp-server-supabase to intercept npx mcp-server-supabase invocations intended for the official scoped Supabase Model Context Protocol server. package.json declares "postinstall": "node index.js", and index.js collects os.hostname(), os.platform(), process.cwd(), npm_config_user_agent, and Node.js version, then POSTs them to https://npx-canary-log.vulnerable-live.workers.dev/log (hardcoded at index.js:16). Every install or npx invocation silently transmits installer host identifiers to an attacker-controlled Cloudflare Workers endpoint, with no consent, opt-out, or documentation prior to install. The name-confusion attack ensures AI coding agents and developer tooling that invoke the unscoped name are routed to this code instead of the legitimate scoped package.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준