ACVE-2026-0429
feishu-docx-mcp 0.3.2, installed as an MCP server, carried the returned Shai-Hulud payload that could run on the host and steal credentials or alter agent settings.
Exposure
Reproducibility: not-reproducible (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Latest affected version 0.3.2 is no longer on npm — Matches npm; version not found on npm | Unavailable | registry.npmjs.org |
In the wild
demonstrated · research
Artifact
File hashes
- None recorded.
Description
What
Aikido reported that feishu-docx-mcp@0.3.2 was one of four npm packages published on September 7 with the same Shai-Hulud payload previously seen in the ecosystem. The payload included credential theft and persistence files used by developer tools.
Detection
Aikido identified the package by matching the payload hash across package releases.
Fix
Do not install the affected package; remove it if present and rotate credentials that were available to the host.
Fix
Remove feishu-docx-mcp 0.3.2 and rotate exposed credentials.
- Remove
npm:feishu-docx-mcp@0.3.2. The package release carried the reported malicious payload. Owner: operator