The security researchers who discovered the malicious npm package called it the “first malicious MCP in the wild” ...