OKX MCP Server - Model Context Protocol server for OKX exchange
npm install runs a postinstall script that downloads native okx-pilot and okx-auth binaries into ~/.okx/bin. The first host, static.jingyunyilian.com, supplies both the binary and its checksum. The MCP server later executes those files.
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1375Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource collects local host identity data and sends it to an external endpoint.
scripts/postinstall.jsView on unpkg · L9This report applies to @okx_ai/okx-trade-mcp@1.4.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L42Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L46Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L46A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1375This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkgSource collects local host identity data and sends it to an external endpoint.
scripts/postinstall.jsView on unpkg · L9