Official Spidra MCP server: AI-powered web scraping, crawling, and search tools for MCP clients
No attack was identified. The server is an MCP client for Spidra scrape, search, and crawl tools, and the install hook only restyles the fastmcp OAuth consent page.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L16Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L16Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/patch-fastmcp-consent.mjsView on unpkgThis report applies to spidra-mcp@0.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L34Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/patch-fastmcp-consent.mjsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L16Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L16