{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0429",
  "aliases": [],
  "published": "2026-09-07T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "feishu-docx-mcp 0.3.2, installed as an MCP server, carried the returned Shai-Hulud payload that could run on the host and steal credentials or alter agent settings.",
  "details": "## What\n\nAikido reported that `feishu-docx-mcp@0.3.2` was one of four npm packages published on September 7 with the same Shai-Hulud payload previously seen in the ecosystem. The payload included credential theft and persistence files used by developer tools.\n\n## Detection\n\nAikido identified the package by matching the payload hash across package releases.\n\n## Fix\n\nDo not install the affected package; remove it if present and rotate credentials that were available to the host.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "feishu-docx-mcp"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0.3.2"
            }
          ]
        }
      ],
      "versions": [
        "0.3.2"
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.aikido.dev/blog/shai-hulud-npm-resurfaces"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "artifact",
      "vulnClasses": [
        "supply-chain",
        "credential-theft"
      ],
      "cwe": [
        "CWE-506"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI04"
        ],
        "atlas": [
          "AML.T0010.005",
          "AML.T0011.001",
          "AML.T0055"
        ]
      },
      "cveBoundary": "artifact",
      "noCveReason": "A malicious npm package is not assigned a CVE in the public report.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.aikido.dev/blog/shai-hulud-npm-resurfaces",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Remove feishu-docx-mcp 0.3.2 and rotate exposed credentials.",
        "actions": [
          {
            "type": "remove",
            "target": "npm:feishu-docx-mcp@0.3.2",
            "why": "The package release carried the reported malicious payload.",
            "owner": "operator"
          }
        ]
      },
      "artifact": {
        "payload": {
          "class": "credential-theft",
          "delivery": "companion-script",
          "c2": [],
          "target": "host running the MCP server"
        },
        "platformStatus": {
          "platform": "npm",
          "status": "unknown",
          "flaggedBy": [
            "Aikido"
          ],
          "downloadable": null,
          "checkedAt": "2026-09-24T00:00:00Z"
        },
        "fileHashes": [],
        "provenance": {
          "researcherCreated": false,
          "reporter": "Aikido"
        }
      },
      "exposure": {
        "harness": {
          "value": "Any host that installs or runs feishu-docx-mcp 0.3.2",
          "any": true,
          "status": "confirmed",
          "source": "https://www.aikido.dev/blog/shai-hulud-npm-resurfaces"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any task that installs or invokes the MCP server",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "feishu-docx-mcp 0.3.2 and its package payload, including developer-tool settings files",
          "status": "confirmed",
          "source": "https://www.aikido.dev/blog/shai-hulud-npm-resurfaces"
        },
        "approval": {
          "value": "Package code runs without an agent approval step once installed",
          "mode": "none-required",
          "status": "detected",
          "source": "https://www.aikido.dev/blog/shai-hulud-npm-resurfaces"
        },
        "inputControl": "package-publisher",
        "agentAction": "The host runs the package payload, which can steal credentials and write persistence settings.",
        "harm": "credential-theft",
        "divergence": "none"
      },
      "claims": [
        {
          "kind": "installable",
          "statement": "Latest affected version 0.3.2 is no longer on npm",
          "value": "0.3.2",
          "status": "detected",
          "source": "https://registry.npmjs.org/feishu-docx-mcp/0.3.2",
          "result": "unavailable",
          "observed": "npm: version does not exist",
          "method": "machine"
        }
      ],
      "reproducibility": {
        "status": "not-reproducible",
        "axesComplete": true,
        "componentsObtainable": false,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
