PkgRadar

npm · registry.npmjs.org

it-tools-mcp

DNS / OAST exfiltration: matched "dns.resolve"

Why PkgRadar flagged 5.10.7

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.resolve" · package/build/tools/network/dig/index.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/build/tools/network/nslookup/index.js
highCredential file accessmatched ".ssh" · package/build/tools/network/scp/index.js
highCredential file accessmatched ".ssh" · package/build/tools/network/ssh/index.js
highInstall Lifecycle Remote Or Execprepare="bash -lc 'if [ -f scripts/install-pre-commit.sh ]; then bash scripts/install-pre-commit.sh; else echo \"Skipping install-pre-commit; script missing\"; fi'" · package.json
mediumRemote Payloadmatched "curl " · package/build/index.js
mediumRemote Payloadmatched "curl\n\n" · package/build/tools/ansible/show_ansible_reference/index.js
mediumRemote Payloadmatched "curl " · package/build/tools/crypto/generate_basic_auth/index.js
mediumRemote Payloadmatched "curl " · package/build/tools/network/curl/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.10.7Review1882026-05-24
5.10.8Review1882026-05-24

Related campaigns

Block this in CI

PkgRadar gates it-tools-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]