MCP Registry

plumery

175a73ed-fdb1-5dc9-b10d-b09e9b9ab630 | v3.12.0
98/ 100
CRITICAL risk
No change since v3.9.0
Risk verdict
Do not install

Score-based assessment (critical risk, 98/100). Last analyst review covers version unknown.

Analysis record

Analysed
1 weeks ago
Version
v3.12.0
Artifact
SHA256 98F…76A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

695 detail rows

YARA Rule Matches

11 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 8
internal/utils/env.jsclient.d.tsinternal/utils/env.mjs +5 more
-
LOWpostinstall persistence mechanism 6
src/core/error.tssrc/resources/shared.tsresources/shared.d.mts +3 more
-
LOWUsingCommandLineArguments 1
bin/cli
-
LOWpostinstall file download 69
resources/parties/accounts/accounts.mjsresources/parties/individuals/tax-identifications.d.mtsinternal/types.d.ts +66 more
-
LOWNoUseWeakRandom 6
src/internal/utils/uuid.tsclient.jssrc/client.ts +3 more
-
LOWpostinstall obfuscation 157
src/resources/auth/password/password.tsresources/auth/challenges/cross-device.d.mtsresources/mfa/device-signature/pending.d.ts +154 more
-
LOWpostinstall network communication 96
resources/staff/permissions.d.mtsresources/auth/auth.d.tscore/error.js +93 more
-
LOWpostinstall system command 75
resources/parties/standing-orders.mjsresources/staff/roles/roles.d.tsresources/parties/quotes.d.mts +72 more
-
LOWpostinstall file manipulation 157
internal/request-options.d.mtsresources/staff/auth.mjsresources/devices/index.d.ts +154 more
-
LOWpostinstall crypto operations 36
src/resources/parties/cards/cards.tssrc/resources/user-enrolments/user-enrolments.tscore/error.d.ts +33 more
-
LOWpostinstall environment access 74
resources/auth/auth.d.mtsresources/parties/cards/cards.d.tsresources/parties/cards/cards.d.mts +71 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

758 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

8
Secrets
2
Network
758
IoC Indicators

YARA Rules Matched

11 rules(685 hits)
credential env files postinstall persistence mechanism UsingCommandLineArguments postinstall file download NoUseWeakRandom postinstall obfuscation postinstall network communication postinstall system command postinstall file manipulation postinstall crypto operations postinstall environment access

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category credential theft; evidence quality strong.

This package presents an extreme security risk and should be treated as an active threat. Unlike typical SDKs that might trigger noise from IoC scanners or code-smell rules, 'plumery' exhibits indicators of confirmed malicious activity: it has 8 critical secret findings and 545 high-severity malware signature hits. While legitimate bundles often flag numerous IoCs (domains, IPs) and code-smell findings (e.g., 'eval', 'env access'), they do not trigger high-severity malware signatures. The presence of 545 malware signatures, combined with 8 critical secrets, strongly suggests this is either a trojanized dependency designed to harvest and exfiltrate credentials or a known malware family being distributed under the guise of a legitimate API library. The 'official' naming and 'unknown' version further align with typosquatting or brand impersonation tactics. There is no legitimate reason for a standard TypeScript API library to trigger this volume of high-severity malware heuristics.

Key Reasons

  • 545 high-severity malware signature hits are definitive indicators of malicious code/payloads
  • 8 critical secret findings (credentials) suggest active harvesting or hardcoded backdoors
  • Extreme risk score (100) and trust score (0) correlate with confirmed threat patterns
  • Metadata (unknown version, 'official' description) is consistent with typosquatting/supply chain attacks
  • Tool-poisoning count is zero, ruling out standard library/SDK false positive patterns

False Positive Considerations

  • High volume of IoCs (1515) are likely bundled dependencies in dist/
  • Medium severity findings are likely generic code patterns

Reviewed 2026-04-12; recommended action: takedown request; model confidence 92%.

MCP version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
98
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
3.6.0
May 19, 2026
Risk range
98 to 98
Across analyzed versions
Latest analyzed version
3.12.0
Sep 22, 2026
Selected version
critical
Version
v3.12.0
1 weeks ago
Risk score
98
Findings
1453
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

The official TypeScript library for the Plumery API

Frequently Asked Questions