PkgRadar

npm · registry.npmjs.org

@getmcpm/cli

Llm Injection Payload: AI-agent-directed instruction adjacent to credential exfil — prompt-injection payload (Shai-Hulud / SANDWORM_MODE). imperative="Ignore all previous instructions" target=".ssh/id_rsa"

Why PkgRadar flagged 0.10.1

SeveritySignalEvidence
highLlm Injection PayloadAI-agent-directed instruction adjacent to credential exfil — prompt-injection payload (Shai-Hulud / SANDWORM_MODE). imperative="Ignore all previous instructions" target=".ssh/id_rsa" · package/dist/runner-GA67S7C5.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.1High risk132026-06-14
0.10.0High risk132026-06-14
0.9.0Review12026-06-10
0.8.1Review12026-06-08
0.8.0Review12026-06-02
0.7.1Review12026-06-02
0.7.0Review12026-06-01
0.5.0Review12026-06-01
0.6.0Review12026-06-01

Block this in CI

PkgRadar gates @getmcpm/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @getmcpm/[email protected]
@getmcpm/cli — npm security scan | PkgRadar