HIGH RISK NaN/100

@messengerflow/mcp-server

Unknown developer

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

HIGH credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-13801

dist/index.js:13801

HIGH credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-13

dist/index.js:13

HIGH credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-13

dist/index.js:13

HIGH Malware Signature

YARA rule match: -credential_env_files

/tmp/extract-6612330d42a5f91419193e1255fb3ac1ee15ea435cf1a8f6d787d0eecf1763dd-809212187/dist/index.js

HIGH Malware Signature

YARA rule match: -postinstall_crypto_operations

/tmp/extract-6612330d42a5f91419193e1255fb3ac1ee15ea435cf1a8f6d787d0eecf1763dd-809212187/dist/index.js

All Findings (113)

View all 113 security findings
credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-13801

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-13

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-13

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_registry_modification

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -NoUseWeakRandom

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-14

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_system_command

Suspicious Network Activity

Network call of type 'socket_io' detected.

network-access

MCP tool poisoning risk: NETWORK-ACCESS-dist/index.js-13832

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected IP: ::

Indicator of Compromise

XIOC detected Domain: issue2.errors.map

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-04/schema#

Indicator of Compromise

XIOC detected URL: https://json-schema.org/draft/2020-12/schema

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-07/schema#

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-04/schema#

Indicator of Compromise

XIOC detected URL: https://auth.messengerflow.com/realms/messengerflow

Indicator of Compromise

XIOC detected URL: https://img.shields.io/npm/v/@messengerflow/mcp-server)](https://www.npmjs.com/package/@messengerflow/mcp-server)

Indicator of Compromise

XIOC detected URL: https://messengerflow.com)

Indicator of Compromise

XIOC detected URL: https://mcp.messengerflow.com/mcp

Indicator of Compromise

XIOC detected URL: https://app.messengerflow.com/api/v1

Indicator of Compromise

XIOC detected URL: https://app.messengerflow.com)

Indicator of Compromise

XIOC detected URL: https://app.messengerflow.com/api/v1

Indicator of Compromise

XIOC detected URL: http://[$

Indicator of Compromise

XIOC detected Domain: numberschema.gt

Indicator of Compromise

XIOC detected Domain: numberschema.lt

Indicator of Compromise

XIOC detected Domain: schema.properties

Indicator of Compromise

XIOC detected Domain: prefixitems.map

Indicator of Compromise

XIOC detected Domain: items.map

Indicator of Compromise

XIOC detected Domain: schema.anyof.map

Indicator of Compromise

XIOC detected Domain: schema.oneof.map

Indicator of Compromise

XIOC detected Domain: inst.rest

Indicator of Compromise

XIOC detected Domain: inst.in

Indicator of Compromise

XIOC detected URL: https://json-schema.org/draft/2020-12/schema

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-07/schema#

Indicator of Compromise

XIOC detected Domain: type.map

Indicator of Compromise

XIOC detected Domain: z.email

Indicator of Compromise

XIOC detected Domain: z.iso.date

Indicator of Compromise

XIOC detected Domain: checks.map

Indicator of Compromise

XIOC detected Domain: inst.email

Indicator of Compromise

XIOC detected Domain: inst.date

Indicator of Compromise

XIOC detected Domain: inst.gt

Indicator of Compromise

XIOC detected Domain: inst.lt

Indicator of Compromise

XIOC detected Domain: inst.int

Indicator of Compromise

XIOC detected Domain: inst.safe

Indicator of Compromise

XIOC detected Domain: mime.map

Indicator of Compromise

XIOC detected Domain: json2.properties

Indicator of Compromise

XIOC detected Domain: def.items.map

Indicator of Compromise

XIOC detected Domain: ctx2.target

Indicator of Compromise

XIOC detected Domain: this.ctx.target

Indicator of Compromise

XIOC detected Domain: this.ctx.io

Indicator of Compromise

XIOC detected Domain: params.io

Indicator of Compromise

XIOC detected Domain: params.case

Indicator of Compromise

XIOC detected Domain: truthyarray.map

Indicator of Compromise

XIOC detected Domain: falsyarray.map

Indicator of Compromise

XIOC detected Domain: ctx.io

Indicator of Compromise

XIOC detected Domain: ctx.target

Indicator of Compromise

XIOC detected Domain: schema.id

Indicator of Compromise

XIOC detected Domain: regexes.map

Indicator of Compromise

XIOC detected Domain: def.in

Indicator of Compromise

XIOC detected Domain: def.parts

Indicator of Compromise

XIOC detected Domain: sizing.unit.one

Indicator of Compromise

XIOC detected Domain: issue2.values.map

Indicator of Compromise

XIOC detected Domain: meta3.id

Indicator of Compromise

XIOC detected Domain: pm.id

Indicator of Compromise

XIOC detected Domain: values.map

Indicator of Compromise

XIOC detected Domain: merged.data

Indicator of Compromise

XIOC detected Domain: def.rest

Indicator of Compromise

XIOC detected Domain: keyresult.issues.map

Indicator of Compromise

XIOC detected Domain: valueresult.issues.map

Indicator of Compromise

XIOC detected Domain: def.values.map

Indicator of Compromise

XIOC detected Domain: inst.constructor.name

Indicator of Compromise

XIOC detected Domain: result2.issues.map

Indicator of Compromise

XIOC detected Domain: content.map

Indicator of Compromise

XIOC detected Domain: r.data

Indicator of Compromise

XIOC detected Domain: catchall.run

Indicator of Compromise

XIOC detected Domain: results.map

Indicator of Compromise

XIOC detected Domain: def.options.map

Indicator of Compromise

XIOC detected Domain: patterns.map

Indicator of Compromise

XIOC detected Domain: sharedvalue.data

Indicator of Compromise

XIOC detected Domain: enumvalues.map

Indicator of Compromise

XIOC detected Domain: curr.properties

Indicator of Compromise

XIOC detected Domain: path.map

Indicator of Compromise

XIOC detected Domain: zod.run

Indicator of Compromise

XIOC detected Domain: result.issues.map

Indicator of Compromise

XIOC detected Domain: def.property

Indicator of Compromise

XIOC detected Domain: lines.map

Indicator of Compromise

XIOC detected Domain: this.name

Indicator of Compromise

XIOC detected Domain: array2.map

Indicator of Compromise

XIOC detected Domain: keys.map

Indicator of Compromise

XIOC detected Domain: object.prototype.hasownproperty.call

Indicator of Compromise

XIOC detected Domain: issues.map

Indicator of Compromise

XIOC detected Domain: obj.constructor.name

Indicator of Compromise

XIOC detected Domain: inst.name

Indicator of Compromise

XIOC detected Domain: img.shields.io

Indicator of Compromise

XIOC detected Domain: mcp.messengerflow.com

Indicator of Compromise

XIOC detected Domain: app.messengerflow.com

Indicator of Compromise

XIOC detected Domain: www.npmjs.com

Indicator of Compromise

XIOC detected Domain: messengerflow.com

Indicator of Compromise

XIOC detected Domain: json-schema.org

Indicator of Compromise

XIOC detected Domain: auth.messengerflow.com

Indicator of Compromise

XIOC detected Domain: cls.name

metadata

HASH-d2292eafdd1cf150

metadata

HASH-b647f4950dac0885

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/9/2026 · Version unknown

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.