Benign canary package for authorized security testing of an MCP scanner. No harmful behavior.
Installation runs a shell command and exfiltrates its output with the host name. Importing the package also triggers the beacon.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs the beacon during installation.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
beacon.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
beacon.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
beacon.jsView on unpkgIt sends the hostname and command output to a third-party webhook.
beacon.jsView on unpkg · L9This report applies to @yongot/canary-mcp-test@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs the beacon during installation.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
beacon.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
beacon.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
beacon.jsView on unpkgIt sends the hostname and command output to a third-party webhook.
beacon.jsView on unpkg · L9