Provenance and supply-chain signals for the 40 most-installed Model Context Protocol packages, plus the Python ecosystem. Regenerated automatically — last run 2026-09-22 10:18 UTC.
Built by mcpaudit. Registry metadata only; nothing is installed or executed. Raw JSON.
Probed 248 homoglyph variants of publisher scopes that npm reserves for official packages.
1 package(s) found impersonating an official scope:
| Package | Impersonates | First published | Maintainer | Declared author |
|---|---|---|---|---|
@modelcontextprotoco1/server-filesystem | @modelcontextprotocol/server-filesystem | 2026-04-13 | eliav.livneh | Anthropic, PBC |
A package under a lookalike scope may be byte-identical to the real one today and hostile tomorrow. Do not install these.
84 package name(s) on the MCP / AI-agent surface have an open, non-withdrawn malware advisory in the GitHub Advisory Database.
Grouped by what actually became of each package, because a flat list of names conflates three very different situations. Read this as "check before you install", not as a verdict. These advisories are largely automated, and automation produces false positives. I inspected one entry on this list — lokal-mcp, flagged critical — and found an 18 KB single-file server with no install hooks, no child_process, no obfuscation, and one outbound host that is its own documented API. It looks entirely legitimate. Its advisory is still open. Treat every row here as a prompt to look, and follow the advisory link before drawing a conclusion about anyone's package.
Scanned 51,718 malware advisories across npm and PyPI in the GitHub Advisory Database. Result truncated by a request cap — treat as a lower bound.
Removed from the registry, or replaced by npm with a security-holding placeholder. The registry took action; this is not an inference.
| Package | Published now | Advisory |
|---|---|---|
marketing-mcp (pip) | — | GHSA-7m86-6729-5w7h |
mcp-search-server (pip) | — | GHSA-3rhm-6v7p-whrg |
wayspiritmcp-weather (pip) | — | GHSA-6h3x-xwcv-w9f9 |
wayspiritmcp-tpa (pip) | — | GHSA-wc92-rjp7-g2h3 |
wayspiritmcp-ppa (pip) | — | GHSA-65cx-x459-79g7 |
wayspiritmcp-enconly (pip) | — | GHSA-rjcm-fv9f-f2rg |
tpvmcpustudy (pip) | — | GHSA-2wm5-3q9g-7g9q |
tpreramcpu (pip) | — | GHSA-8fxp-94rp-3mg3 |
tpmcpongpaypal (pip) | — | GHSA-26vj-4966-5pq5 |
tpmaskmcpush (pip) | — | GHSA-2cv3-mmq9-rqmr |
tpcvmcpy (pip) | — | GHSA-cwhq-gx62-5m8w |
timingmcp (pip) | — | GHSA-r4m9-m2j9-pc96 |
timermcp (pip) | — | GHSA-q5cc-6j33-596w |
timemcp-py (pip) | — | GHSA-6hwf-phjh-8xf6 |
timemcp-utils (pip) | — | GHSA-v3mf-rv4w-3wrj |
timemcp (pip) | — | GHSA-g8xr-2qm9-4rvc |
timemcplib (pip) | — | GHSA-fc22-xmvh-52gc |
timesmcp (pip) | — | GHSA-p38x-hh3f-8m97 |
timermcplib (pip) | — | GHSA-jm7c-w9pg-m3r9 |
timesmcplib (pip) | — | GHSA-rwxf-w5g7-7v4x |
timemcp190825790125120985125 (pip) | — | GHSA-59qw-q72h-7g98 |
timemcp-client (pip) | — | GHSA-293w-f5jh-wc38 |
tiktoken-mcp (pip) | — | GHSA-wj5q-fgqm-2wv6 |
testpackage1mcpe (pip) | — | GHSA-hg9j-p4cc-6q97 |
strands-agents-anthropic (pip) | — | GHSA-vr36-grrv-xgxm |
story-mcp-hub (pip) | — | GHSA-pxhw-g4m2-fw8r |
selfmcpipcpu (pip) | — | GHSA-j824-jwch-j836 |
selfmcproofvisa (pip) | — | GHSA-c7gm-c92f-95hg |
selfhackedmcpong (pip) | — | GHSA-pw74-4r53-jhf8 |
selfhttpmcpush (pip) | — | GHSA-2cqr-77mv-fcwg |
selfccmcpush (pip) | — | GHSA-whwv-cfgr-mmw2 |
ramcpu (pip) | — | GHSA-qpgc-89qw-jqr9 |
py-ultramcpyw (pip) | — | GHSA-rwrc-v842-r2v2 |
py-randomcpu (pip) | — | GHSA-3jwf-g5qm-2q74 |
py-pepmcpaypal (pip) | — | GHSA-h8gm-h4f6-hmp9 |
py-mcpyw (pip) | — | GHSA-7rrc-4g96-p2q3 |
py-mcpushmask (pip) | — | GHSA-v93m-98ch-cvrc |
py-infomcpy (pip) | — | GHSA-mmm9-497c-w755 |
py-cpumcpyw (pip) | — | GHSA-73m3-xf5w-6766 |
openai-mcp (pip) | — | GHSA-h7rx-63j6-3w83 |
mcpsever (pip) | — | GHSA-6wf3-7v76-j8g7 |
mcpyw (pip) | — | GHSA-q667-ccgf-c2rm |
mcp-weather-full (pip) | — | GHSA-23g4-jfwp-rv64 |
mcp-xyz (pip) | — | GHSA-mrf9-fw7v-p98g |
mcp-runcmd-server (pip) | — | GHSA-fqxv-p3pf-c494 |
mcpip (pip) | — | GHSA-vf8x-7v6f-qj5m |
mcpost (pip) | — | GHSA-g25w-q9c7-j7x6 |
mcpep (pip) | — | GHSA-x3j7-c7p2-q6m7 |
mcp-pdftool-plus (pip) | — | GHSA-fh2f-vcxw-gm22 |
mcp-runcommand-server (pip) | — | GHSA-22rf-pqm4-vwxw |
mcp-runcommand-server2 (pip) | — | GHSA-2cvc-xrh7-32gg |
mcp-transport-proto (pip) | — | GHSA-q37q-c4qv-gr6h |
libramcpuhacked (pip) | — | GHSA-995p-r3gh-pw5c |
libmcpingstudy (pip) | — | GHSA-hr7x-4646-hr32 |
libmcpipver (pip) | — | GHSA-56gv-w36g-p92g |
libmcpongvm (pip) | — | GHSA-mj2g-7vxx-x9p9 |
libmcpywcontrol (pip) | — | GHSA-m46c-qp7j-x3x2 |
libmcpep (pip) | — | GHSA-475f-fhrv-6m7w |
libencoderandomcpu (pip) | — | GHSA-vp5v-v237-jcg8 |
libedmcpong (pip) | — | GHSA-5h97-vgh2-wqr9 |
latinum-wallet-mcp (pip) | — | GHSA-7fjp-p82r-q2c2 |
langchain-core-mcp (pip) | — | GHSA-f6f5-m9qw-v738 |
instructor-mcp (pip) | — | GHSA-vp83-46ch-mpvw |
groq-mcp (pip) | — | GHSA-2544-8267-j7f9 |
esqpymcpy (pip) | — | GHSA-v5v2-xrvc-5mqg |
esqmcpypaypal (pip) | — | GHSA-p984-mxw9-86pm |
esqmcpepgrand (pip) | — | GHSA-hc7q-54jj-wpvc |
esqmcpaypallgtb (pip) | — | GHSA-ccq8-3gfx-r64q |
esqmcpullram (pip) | — | GHSA-h336-2qhc-r4f2 |
docontrol-mcp (pip) | — | GHSA-9h3c-vrq8-7p3c |
claude-lite (pip) | — | GHSA-2x8m-pc3r-f9wx |
anthropickit (pip) | — | GHSA-2q9v-5rq6-rmwf |
ant-mcp-proxy-for-test (pip) | — | GHSA-jcv2-j354-7j53 |
@vite-mcp/vite-type (npm) | 0.0.1-security | GHSA-mqf9-3wx8-45cj |
@yongot/canary-mcp-isolation (npm) | 0.0.1-security | GHSA-cr2f-c82j-mj6q |
@yongot/canary-mcp-test-2 (npm) | 0.0.1-security | GHSA-93xr-jvm3-jpch |
@yongot/canary-mcp-test (npm) | 0.0.1-security | GHSA-qjwm-vq22-4xx8 |
feishu-docx-mcp (npm) | 0.0.1-security | GHSA-q5c6-p5q5-g3px |
The version the registry serves today falls inside the advisory's range. These warrant the most caution — and are also where an incorrect advisory does the most damage to an innocent maintainer, so read the advisory before concluding anything.
| Package | Published now | Advisory covers | Advisory |
|---|---|---|---|
vulndify-mcp-server (pip) | 0.3.0 | = 0.3.0 | GHSA-v3x5-574x-8776 |
Listed for completeness only. The maintainer has published a version outside the advisory's range, so the package on the registry today is not the one the advisory describes. Several are well-known projects that were compromised and cleaned up. Do not read this section as a warning about these packages.
| Package | Published now | Advisory covers | Advisory |
|---|---|---|---|
fa-mcp-sdk (npm) | 0.12.96 | = 0.12.72 | GHSA-h524-rpj8-rm5j |
wdt-erpmcp (pip) | 0.2.15 | = 0.1.7 | GHSA-mfjc-6893-4m4j |
ray-mcp-server (pip) | 0.2.0 | = 0.2.1 | GHSA-xpj9-c6mx-gfqf |
The advisory range could not be parsed or the registry did not answer. No conclusion drawn.
| Package | Published now | Advisory covers | Advisory |
|---|---|---|---|
extension-gapcursor (npm) | — | = 213.21.24 | GHSA-q24q-cjrv-vv7x |
extension-dropcursor (npm) | — | = 213.21.24 | GHSA-jghr-9287-664g |
If one of these appears in your MCP config, read its advisory first. Where the advisory holds up — and especially where npm has replaced the package with a security placeholder — treat it as a compromise rather than a warning: remove it, then rotate every credential it could reach.
0 of 40 carry at least one finding. An unpinned official package is low risk; an unpinned unknown one is not.
| Package | Downloads/mo | Age (days) | Worst | Findings |
|---|---|---|---|---|
chrome-devtools-mcp | 7,829,594 | 496 | clean | — |
@storybook/mcp | 7,665,405 | 334 | clean | — |
@upstash/context7-mcp | 3,467,901 | 531 | clean | — |
@modelcontextprotocol/server-filesystem | 2,885,375 | 669 | clean | — |
@pandacss/mcp | 797,848 | 261 | clean | — |
@notionhq/notion-mcp-server | 595,345 | 536 | clean | — |
hostinger-api-mcp | 554,712 | 529 | clean | — |
@azure-devops/mcp | 453,473 | 466 | clean | — |
@sentry/mcp-server | 404,489 | 515 | clean | — |
@supabase/mcp-server-supabase | 401,712 | 542 | clean | — |
@sap-ux/fiori-mcp-server | 319,373 | 384 | clean | — |
@ui5/mcp-server | 316,297 | 384 | clean | — |
@transcend-io/mcp-server-consent | 219,638 | 152 | clean | — |
@transcend-io/mcp-server-admin | 219,387 | 152 | clean | — |
@transcend-io/mcp-server-preferences | 219,342 | 152 | clean | — |
@transcend-io/mcp-server-inventory | 219,229 | 152 | clean | — |
@transcend-io/mcp-server-workflows | 219,104 | 152 | clean | — |
@transcend-io/mcp-server-base | 217,903 | 152 | clean | — |
@transcend-io/mcp-server-assessment | 217,466 | 152 | clean | — |
@transcend-io/mcp-server-dsr | 217,376 | 152 | clean | — |
@transcend-io/mcp-server-discovery | 217,160 | 152 | clean | — |
@transcend-io/mcp-server-docs | 215,758 | 76 | clean | — |
@cap-js/mcp-server | 203,074 | 384 | clean | — |
@currents/mcp | 135,770 | 536 | clean | — |
scryfall-mcp-server | 114,542 | 586 | clean | — |
@ericthered926/duckduckgo-mcp-server | 108,923 | 278 | clean | — |
@apify/actors-mcp-server | 107,929 | 613 | clean | — |
@aikidosec/mcp | 105,451 | 292 | clean | — |
@winor30/mcp-server-datadog | 93,863 | 575 | clean | — |
@hubspot/mcp-server | 82,408 | 514 | clean | — |
@shortcut/mcp | 74,782 | 552 | clean | — |
@eslint/mcp | 68,897 | 495 | clean | — |
@z_ai/mcp-server | 64,357 | 379 | clean | — |
@browserstack/mcp-server | 59,287 | 517 | clean | — |
dataforseo-mcp-server | 54,288 | 497 | clean | — |
@zencoderai/slack-mcp-server | 51,612 | 432 | clean | — |
mcp-server-kubernetes | 36,638 | 651 | clean | — |
kubernetes-mcp-server | 33,874 | 584 | clean | — |
@heroku/mcp-server | 30,456 | 532 | clean | — |
@xeroapi/xero-mcp-server | 28,136 | 550 | clean | — |
| Package | Downloads/mo | Age (days) | Worst | Findings |
|---|---|---|---|---|
mcp | 0 | 670 | clean | — |
fastmcp | 0 | 661 | clean | — |
mcp-server-fetch | 0 | 668 | clean | — |
mcp-server-git | 142,306 | 669 | clean | — |
mcp-server-time | 457,705 | 661 | clean | — |
mcp-server-sqlite | 0 | 669 | clean | — |
npx github:AndrewXuTurtle/mcpaudit
Scans every MCP config on your system — Claude Desktop, Claude Code, Cursor, Windsurf, VS Code.