PkgRadar

npm · registry.npmjs.org

@namncqualgo/secure-code-mcp

DNS / OAST exfiltration: matched "oastify.com"

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "oastify.com" · package/data/vulnerabilities/osv/pypi/GHSA-f776-fp4w-266c.json
highDNS / OAST exfiltrationmatched "oastify.com" · package/data/vulnerabilities/osv/npm/GHSA-p4fx-23fq-jfg6.json
highDNS / OAST exfiltrationmatched "oastify.com" · package/data/vulnerabilities/osv/npm/MAL-2025-49410.json
highDNS / OAST exfiltrationmatched "oastify.com" · package/data/vulnerabilities/osv/npm/MAL-2026-3724.json
highDNS / OAST exfiltrationmatched "oastify.com" · package/data/vulnerabilities/osv/npm/MAL-2026-3749.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0High risk1392026-06-10
0.2.0High risk1392026-06-10
0.1.0High risk1392026-06-10
0.4.0Review182026-06-04
0.3.1Review182026-06-03

Block this in CI

PkgRadar gates @namncqualgo/secure-code-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @namncqualgo/[email protected]