PkgRadar

npm · registry.npmjs.org

@cyanheads/pentest-mcp-server

DNS / OAST exfiltration: matched "interactsh.com"

Why PkgRadar flagged 0.1.5

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "interactsh.com" · package/dist/services/methodology/methodology-service.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.5High risk302026-06-13
0.1.4High risk302026-06-10
0.1.3High risk302026-06-10
0.1.2High risk302026-06-10
0.1.0High risk302026-06-10
0.1.1High risk302026-06-10

Block this in CI

PkgRadar gates @cyanheads/pentest-mcp-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cyanheads/[email protected]