{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0441",
  "aliases": [],
  "published": "2026-09-08T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "gadgethumans-mcp 1.0.9, installed to provide x402 payments, sent the configured wallet private key to its remote MCP endpoint instead of signing a payment locally.",
  "details": "## What\n\nKnostic's analysis found that `gadgethumans-mcp@1.0.9` reads `WALLET_PRIVATE_KEY` and puts the raw value in an HTTP header on outbound MCP requests. The package did not perform local signing, and Knostic found no evidence of stolen funds or confirmed victims.\n\n## Detection\n\nThe source provides static code evidence and package-download context. Not recreated in a lab.\n\n## Fix\n\nRemove gadgethumans-mcp 1.0.9, rotate the wallet key and do not give unreviewed MCP servers wallet-signing secrets.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "gadgethumans-mcp"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "1.0.9"
            }
          ]
        }
      ],
      "versions": [
        "1.0.9"
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "artifact",
      "vulnClasses": [
        "credential-theft",
        "supply-chain",
        "data-exfiltration"
      ],
      "cwe": [
        "CWE-506",
        "CWE-522"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI04",
          "ASI03"
        ],
        "atlas": [
          "AML.T0110.001",
          "AML.T0083"
        ]
      },
      "cveBoundary": "artifact",
      "noCveReason": "A malicious npm package is not assigned a CVE in the public report.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Remove gadgethumans-mcp 1.0.9 and rotate the configured wallet key.",
        "actions": [
          {
            "type": "remove",
            "target": "npm:gadgethumans-mcp@1.0.9",
            "why": "The package transmits the raw wallet key.",
            "owner": "operator"
          }
        ]
      },
      "artifact": {
        "payload": {
          "class": "credential-theft",
          "delivery": "companion-script",
          "c2": [],
          "target": "host and configured wallet"
        },
        "platformStatus": {
          "platform": "npm",
          "status": "unknown",
          "flaggedBy": [
            "Knostic"
          ],
          "downloadable": null,
          "checkedAt": "2026-09-24T00:00:00Z"
        },
        "fileHashes": [],
        "provenance": {
          "researcherCreated": false,
          "reporter": "Knostic"
        }
      },
      "exposure": {
        "harness": {
          "value": "Any MCP client or host that installs gadgethumans-mcp 1.0.9",
          "any": true,
          "status": "confirmed",
          "source": "https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any MCP tool call made with a wallet key configured",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "The MCP server, WALLET_PRIVATE_KEY environment variable and its outbound payment request",
          "status": "confirmed",
          "source": "https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm"
        },
        "approval": {
          "value": "The package sends the configured key as part of its request without a separate approval step",
          "mode": "none-required",
          "status": "confirmed",
          "source": "https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm"
        },
        "inputControl": "package-publisher",
        "agentAction": "The MCP server transmits the configured wallet private key to its endpoint.",
        "harm": "credential-theft",
        "divergence": "none",
        "reach": {
          "value": "The wallet controlled by the configured private key",
          "kinds": [
            "wallet",
            "funds"
          ],
          "status": "confirmed",
          "source": "https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-malicious-mcp-package-on-npm"
        }
      },
      "claims": [
        {
          "kind": "installable",
          "statement": "Latest affected version 1.0.9 is still installable from npm",
          "value": "1.0.9",
          "status": "confirmed",
          "source": "https://registry.npmjs.org/gadgethumans-mcp/1.0.9",
          "result": "match",
          "observed": "npm: version exists",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:33Z"
        }
      ],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": true,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "trigger not published"
        ]
      }
    }
  }
}
