MCP Package Trust Index

Provenance and supply-chain signals for the 40 most-installed Model Context Protocol packages, plus the Python ecosystem. Regenerated automatically — last run 2026-09-22 10:18 UTC.

Built by mcpaudit. Registry metadata only; nothing is installed or executed. Raw JSON.

Impersonation sweep

Probed 248 homoglyph variants of publisher scopes that npm reserves for official packages.

1 package(s) found impersonating an official scope:

PackageImpersonatesFirst publishedMaintainerDeclared author
@modelcontextprotoco1/server-filesystem@modelcontextprotocol/server-filesystem2026-04-13eliav.livnehAnthropic, PBC

A package under a lookalike scope may be byte-identical to the real one today and hostile tomorrow. Do not install these.

MCP packages with published malware advisories

84 package name(s) on the MCP / AI-agent surface have an open, non-withdrawn malware advisory in the GitHub Advisory Database.

Grouped by what actually became of each package, because a flat list of names conflates three very different situations. Read this as "check before you install", not as a verdict. These advisories are largely automated, and automation produces false positives. I inspected one entry on this list — lokal-mcp, flagged critical — and found an 18 KB single-file server with no install hooks, no child_process, no obfuscation, and one outbound host that is its own documented API. It looks entirely legitimate. Its advisory is still open. Treat every row here as a prompt to look, and follow the advisory link before drawing a conclusion about anyone's package.

Scanned 51,718 malware advisories across npm and PyPI in the GitHub Advisory Database. Result truncated by a request cap — treat as a lower bound.

Registry has acted — 78

Removed from the registry, or replaced by npm with a security-holding placeholder. The registry took action; this is not an inference.

PackagePublished nowAdvisory
marketing-mcp (pip)GHSA-7m86-6729-5w7h
mcp-search-server (pip)GHSA-3rhm-6v7p-whrg
wayspiritmcp-weather (pip)GHSA-6h3x-xwcv-w9f9
wayspiritmcp-tpa (pip)GHSA-wc92-rjp7-g2h3
wayspiritmcp-ppa (pip)GHSA-65cx-x459-79g7
wayspiritmcp-enconly (pip)GHSA-rjcm-fv9f-f2rg
tpvmcpustudy (pip)GHSA-2wm5-3q9g-7g9q
tpreramcpu (pip)GHSA-8fxp-94rp-3mg3
tpmcpongpaypal (pip)GHSA-26vj-4966-5pq5
tpmaskmcpush (pip)GHSA-2cv3-mmq9-rqmr
tpcvmcpy (pip)GHSA-cwhq-gx62-5m8w
timingmcp (pip)GHSA-r4m9-m2j9-pc96
timermcp (pip)GHSA-q5cc-6j33-596w
timemcp-py (pip)GHSA-6hwf-phjh-8xf6
timemcp-utils (pip)GHSA-v3mf-rv4w-3wrj
timemcp (pip)GHSA-g8xr-2qm9-4rvc
timemcplib (pip)GHSA-fc22-xmvh-52gc
timesmcp (pip)GHSA-p38x-hh3f-8m97
timermcplib (pip)GHSA-jm7c-w9pg-m3r9
timesmcplib (pip)GHSA-rwxf-w5g7-7v4x
timemcp190825790125120985125 (pip)GHSA-59qw-q72h-7g98
timemcp-client (pip)GHSA-293w-f5jh-wc38
tiktoken-mcp (pip)GHSA-wj5q-fgqm-2wv6
testpackage1mcpe (pip)GHSA-hg9j-p4cc-6q97
strands-agents-anthropic (pip)GHSA-vr36-grrv-xgxm
story-mcp-hub (pip)GHSA-pxhw-g4m2-fw8r
selfmcpipcpu (pip)GHSA-j824-jwch-j836
selfmcproofvisa (pip)GHSA-c7gm-c92f-95hg
selfhackedmcpong (pip)GHSA-pw74-4r53-jhf8
selfhttpmcpush (pip)GHSA-2cqr-77mv-fcwg
selfccmcpush (pip)GHSA-whwv-cfgr-mmw2
ramcpu (pip)GHSA-qpgc-89qw-jqr9
py-ultramcpyw (pip)GHSA-rwrc-v842-r2v2
py-randomcpu (pip)GHSA-3jwf-g5qm-2q74
py-pepmcpaypal (pip)GHSA-h8gm-h4f6-hmp9
py-mcpyw (pip)GHSA-7rrc-4g96-p2q3
py-mcpushmask (pip)GHSA-v93m-98ch-cvrc
py-infomcpy (pip)GHSA-mmm9-497c-w755
py-cpumcpyw (pip)GHSA-73m3-xf5w-6766
openai-mcp (pip)GHSA-h7rx-63j6-3w83
mcpsever (pip)GHSA-6wf3-7v76-j8g7
mcpyw (pip)GHSA-q667-ccgf-c2rm
mcp-weather-full (pip)GHSA-23g4-jfwp-rv64
mcp-xyz (pip)GHSA-mrf9-fw7v-p98g
mcp-runcmd-server (pip)GHSA-fqxv-p3pf-c494
mcpip (pip)GHSA-vf8x-7v6f-qj5m
mcpost (pip)GHSA-g25w-q9c7-j7x6
mcpep (pip)GHSA-x3j7-c7p2-q6m7
mcp-pdftool-plus (pip)GHSA-fh2f-vcxw-gm22
mcp-runcommand-server (pip)GHSA-22rf-pqm4-vwxw
mcp-runcommand-server2 (pip)GHSA-2cvc-xrh7-32gg
mcp-transport-proto (pip)GHSA-q37q-c4qv-gr6h
libramcpuhacked (pip)GHSA-995p-r3gh-pw5c
libmcpingstudy (pip)GHSA-hr7x-4646-hr32
libmcpipver (pip)GHSA-56gv-w36g-p92g
libmcpongvm (pip)GHSA-mj2g-7vxx-x9p9
libmcpywcontrol (pip)GHSA-m46c-qp7j-x3x2
libmcpep (pip)GHSA-475f-fhrv-6m7w
libencoderandomcpu (pip)GHSA-vp5v-v237-jcg8
libedmcpong (pip)GHSA-5h97-vgh2-wqr9
latinum-wallet-mcp (pip)GHSA-7fjp-p82r-q2c2
langchain-core-mcp (pip)GHSA-f6f5-m9qw-v738
instructor-mcp (pip)GHSA-vp83-46ch-mpvw
groq-mcp (pip)GHSA-2544-8267-j7f9
esqpymcpy (pip)GHSA-v5v2-xrvc-5mqg
esqmcpypaypal (pip)GHSA-p984-mxw9-86pm
esqmcpepgrand (pip)GHSA-hc7q-54jj-wpvc
esqmcpaypallgtb (pip)GHSA-ccq8-3gfx-r64q
esqmcpullram (pip)GHSA-h336-2qhc-r4f2
docontrol-mcp (pip)GHSA-9h3c-vrq8-7p3c
claude-lite (pip)GHSA-2x8m-pc3r-f9wx
anthropickit (pip)GHSA-2q9v-5rq6-rmwf
ant-mcp-proxy-for-test (pip)GHSA-jcv2-j354-7j53
@vite-mcp/vite-type (npm)0.0.1-securityGHSA-mqf9-3wx8-45cj
@yongot/canary-mcp-isolation (npm)0.0.1-securityGHSA-cr2f-c82j-mj6q
@yongot/canary-mcp-test-2 (npm)0.0.1-securityGHSA-93xr-jvm3-jpch
@yongot/canary-mcp-test (npm)0.0.1-securityGHSA-qjwm-vq22-4xx8
feishu-docx-mcp (npm)0.0.1-securityGHSA-q5c6-p5q5-g3px

Affected version is still published — 1

The version the registry serves today falls inside the advisory's range. These warrant the most caution — and are also where an incorrect advisory does the most damage to an innocent maintainer, so read the advisory before concluding anything.

PackagePublished nowAdvisory coversAdvisory
vulndify-mcp-server (pip)0.3.0= 0.3.0GHSA-v3x5-574x-8776

Already remediated — 3

Listed for completeness only. The maintainer has published a version outside the advisory's range, so the package on the registry today is not the one the advisory describes. Several are well-known projects that were compromised and cleaned up. Do not read this section as a warning about these packages.

PackagePublished nowAdvisory coversAdvisory
fa-mcp-sdk (npm)0.12.96= 0.12.72GHSA-h524-rpj8-rm5j
wdt-erpmcp (pip)0.2.15= 0.1.7GHSA-mfjc-6893-4m4j
ray-mcp-server (pip)0.2.0= 0.2.1GHSA-xpj9-c6mx-gfqf

Undetermined — 2

The advisory range could not be parsed or the registry did not answer. No conclusion drawn.

PackagePublished nowAdvisory coversAdvisory
extension-gapcursor (npm)= 213.21.24GHSA-q24q-cjrv-vv7x
extension-dropcursor (npm)= 213.21.24GHSA-jghr-9287-664g

If one of these appears in your MCP config, read its advisory first. Where the advisory holds up — and especially where npm has replaced the package with a security placeholder — treat it as a compromise rather than a warning: remove it, then rotate every credential it could reach.

npm packages

0 of 40 carry at least one finding. An unpinned official package is low risk; an unpinned unknown one is not.

PackageDownloads/moAge (days)WorstFindings
chrome-devtools-mcp7,829,594496clean
@storybook/mcp7,665,405334clean
@upstash/context7-mcp3,467,901531clean
@modelcontextprotocol/server-filesystem2,885,375669clean
@pandacss/mcp797,848261clean
@notionhq/notion-mcp-server595,345536clean
hostinger-api-mcp554,712529clean
@azure-devops/mcp453,473466clean
@sentry/mcp-server404,489515clean
@supabase/mcp-server-supabase401,712542clean
@sap-ux/fiori-mcp-server319,373384clean
@ui5/mcp-server316,297384clean
@transcend-io/mcp-server-consent219,638152clean
@transcend-io/mcp-server-admin219,387152clean
@transcend-io/mcp-server-preferences219,342152clean
@transcend-io/mcp-server-inventory219,229152clean
@transcend-io/mcp-server-workflows219,104152clean
@transcend-io/mcp-server-base217,903152clean
@transcend-io/mcp-server-assessment217,466152clean
@transcend-io/mcp-server-dsr217,376152clean
@transcend-io/mcp-server-discovery217,160152clean
@transcend-io/mcp-server-docs215,75876clean
@cap-js/mcp-server203,074384clean
@currents/mcp135,770536clean
scryfall-mcp-server114,542586clean
@ericthered926/duckduckgo-mcp-server108,923278clean
@apify/actors-mcp-server107,929613clean
@aikidosec/mcp105,451292clean
@winor30/mcp-server-datadog93,863575clean
@hubspot/mcp-server82,408514clean
@shortcut/mcp74,782552clean
@eslint/mcp68,897495clean
@z_ai/mcp-server64,357379clean
@browserstack/mcp-server59,287517clean
dataforseo-mcp-server54,288497clean
@zencoderai/slack-mcp-server51,612432clean
mcp-server-kubernetes36,638651clean
kubernetes-mcp-server33,874584clean
@heroku/mcp-server30,456532clean
@xeroapi/xero-mcp-server28,136550clean

PyPI packages

PackageDownloads/moAge (days)WorstFindings
mcp0670clean
fastmcp0661clean
mcp-server-fetch0668clean
mcp-server-git142,306669clean
mcp-server-time457,705661clean
mcp-server-sqlite0669clean

Check your own machine

npx github:AndrewXuTurtle/mcpaudit

Scans every MCP config on your system — Claude Desktop, Claude Code, Cursor, Windsurf, VS Code.