An npx confusion or binary-planting weakness can cause npm to fetch and run an attacker-controlled public package when a requested executable is absent locally. The risk is acute for scoped packages that expose unscoped command names: an attacker can register the corresponding unscoped package name and potentially hijack developer invocations, resulting in arbitrary code execution. A reported proof of concept found that Brave’s @brave/brave-search-mcp-server exposed an unclaimed brave-search-mcp-server binary name that could be targeted through public npm resolution.
The same resolution behavior previously affected Vue CLI, where registration of vue-cli-service could have redirected use of the binary provided by @vue/cli-service. Vue updated its guidance to prevent automatic installation of missing packages:
npx --no vue-cli-service
Organizations should reserve unscoped package and binary names for scoped tools, require explicit scoped invocations, enforce private-registry scoping, and scan repositories and CI/CD workflows for unsafe npx command resolution.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
The research reported potential dependency-confusion risks in OpenAI repositories involving `mapbox-gl.css` and `react-datepicker.css`, and reported internal-tooling or scope-mismatch risks at Stripe, Shopify, Elastic, and Replit involving unreserved names or legacy CLI aliases.
Brave Software was notified about the reported package-name and executable-name mismatch. The company reportedly considered the issue informative because its own infrastructure was not affected.
The researcher reported publishing a harmless `brave-search-mcp-server` proof-of-concept package with a postinstall callback. During local testing, the callback recorded execution on a Windows x64 host running Node.js v24.12.0.
An audit reportedly found that Brave Software's `@brave/brave-search-mcp-server` version 1.2.13 exposed the unscoped `brave-search-mcp-server` executable while the identically named public npm package was unclaimed. This could cause `npx brave-search-mcp-server` to retrieve a public package if no local executable exists.
The npxconfuse open-source scanner was presented as a tool for identifying unclaimed npm package and executable names in local repositories, GitHub organizations, web assets, and package lists. It checks command invocations and scoped-package binary names against npm registry availability.
Vue.js and Vite core-team member Haoqun Jiang updated Vue CLI documentation to recommend `npx --no vue-cli-service`. The change prevents npx from automatically installing a separately registered `vue-cli-service` package when the expected local executable is absent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
lab.ctbb.show
Open sourcenodejs-security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.