HIGH RISK NaN/100

apisql-mcp

Unknown developer

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

CRITICAL hardcoded-token

MCP transport security issue: HARDCODED-TOKEN-bin/server/index.js

bin/server/index.js

HIGH Malware Signature

YARA rule match: -postinstall_network_communication

/tmp/extract-5e517762c16a3bb3528aaa4a22e898e47586ac37ce1acc1ee170c5c95e41548a-3494853349/bin/transports/stdio.js

HIGH Malware Signature

YARA rule match: -postinstall_file_manipulation

/tmp/extract-5e517762c16a3bb3528aaa4a22e898e47586ac37ce1acc1ee170c5c95e41548a-3494853349/README.md

HIGH Malware Signature

YARA rule match: -postinstall_network_communication

/tmp/extract-5e517762c16a3bb3528aaa4a22e898e47586ac37ce1acc1ee170c5c95e41548a-3494853349/README.md

HIGH Malware Signature

YARA rule match: -postinstall_system_command

/tmp/extract-5e517762c16a3bb3528aaa4a22e898e47586ac37ce1acc1ee170c5c95e41548a-3494853349/README.md

All Findings (111)

View all 111 security findings
hardcoded-token

MCP transport security issue: HARDCODED-TOKEN-bin/server/index.js

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_system_command

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-bin/server/index.js-12

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-bin/server/index.js-14

Malware Signature

YARA rule match: -HavingAPermissiveCrossOriginResourceSharingPolicy

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-bin/server/index.js-13

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-bin/server/index.js-13

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_system_command

Indicator of Compromise

XIOC detected IP: ::c

Indicator of Compromise

XIOC detected IP: 5::

Indicator of Compromise

XIOC detected IP: 0.0.0.0

Indicator of Compromise

XIOC detected URL: https://github.com/apisql-dev/apisql-mcp#readme

Indicator of Compromise

XIOC detected MD5 Hash: 7dd9b66d38f8aff81f091ecfcf259f70

Indicator of Compromise

XIOC detected URL: https://docs.apisql.cn)

Indicator of Compromise

XIOC detected URL: https://github.com/apisql-dev/apisql-mcp/issues)

Indicator of Compromise

XIOC detected URL: https://www.npmjs.com/package/apisql-mcp)

Indicator of Compromise

XIOC detected URL: https://www.apisql.cn)

Indicator of Compromise

XIOC detected URL: https://open.apisql.cn/api/mytest/$sudb';

Indicator of Compromise

XIOC detected URL: https://open.apisql.cn/api/mytest/$sudb')

Indicator of Compromise

XIOC detected URL: https://github.com/apisql-dev/apisql-mcp.git

Indicator of Compromise

XIOC detected URL: https://raw.githubusercontent.com/apisql-dev/apisql-mcp/main/images/banner.jpg)](https://www.apisql.cn)

Indicator of Compromise

XIOC detected URL: https://open.apisql.cn/api/mytest/$sudb

Indicator of Compromise

XIOC detected URL: https://open.apisql.cn)

Indicator of Compromise

XIOC detected URL: https://docs.apisql.cn/apisql/010@%E5%85%A5%E9%97%A8/020@%E5%BF%AB%E9%80%9F%E5%85%A5%E9%97%A8/readme.html)

Indicator of Compromise

XIOC detected URL: https://open.apisql.cn/api/mytest/$sudb

Indicator of Compromise

XIOC detected URL: https://open.apisql.cn/api/mytest/$sudb

Indicator of Compromise

XIOC detected URL: https://github.com/apisql-dev/apisql-mcp.git

Indicator of Compromise

XIOC detected Domain: c18.ma

Indicator of Compromise

XIOC detected Domain: apisql.cn

Indicator of Compromise

XIOC detected Domain: readme.md

Indicator of Compromise

XIOC detected IP: a::

Indicator of Compromise

XIOC detected IP: 9::b

Indicator of Compromise

XIOC detected URL: https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)

Indicator of Compromise

XIOC detected URL: https://img.shields.io/badge/node-%3E%3D18.0.0-brightgreen.svg)](https://nodejs.org/)

Indicator of Compromise

XIOC detected Domain: ȩ.fj

Indicator of Compromise

XIOC detected Domain: 86.ni

Indicator of Compromise

XIOC detected Domain: z.nr

Indicator of Compromise

XIOC detected Domain: r.mv

Indicator of Compromise

XIOC detected Domain: l.io

Indicator of Compromise

XIOC detected Domain: o.mk

Indicator of Compromise

XIOC detected Domain: 4h.is

Indicator of Compromise

XIOC detected Domain: ꡔkc.et

Indicator of Compromise

XIOC detected Domain: m.zm

Indicator of Compromise

XIOC detected Domain: 1.so

Indicator of Compromise

XIOC detected Domain: w.kz

Indicator of Compromise

XIOC detected Domain: bnn.bb

Indicator of Compromise

XIOC detected Domain: 6.tl

Indicator of Compromise

XIOC detected Domain: h.aaa

Indicator of Compromise

XIOC detected Domain: request.params.arguments.sc

Indicator of Compromise

XIOC detected Domain: axiosinstance.post

Indicator of Compromise

XIOC detected Domain: response.data

Indicator of Compromise

XIOC detected Domain: ӕ.mw

Indicator of Compromise

XIOC detected Domain: y.gg

Indicator of Compromise

XIOC detected Domain: g.mr

Indicator of Compromise

XIOC detected Domain: vo0.vc

Indicator of Compromise

XIOC detected Domain: www.npmjs.com

Indicator of Compromise

XIOC detected Domain: opensource.org

Indicator of Compromise

XIOC detected Domain: nodejs.org

Indicator of Compromise

XIOC detected Domain: www.apisql.cn

Indicator of Compromise

XIOC detected Domain: options.host

Indicator of Compromise

XIOC detected Domain: args.sc

Indicator of Compromise

XIOC detected Domain: request.params.name

Indicator of Compromise

XIOC detected IP: 8::b

Indicator of Compromise

XIOC detected IP: 18::

Indicator of Compromise

XIOC detected Domain: img.shields.io

Indicator of Compromise

XIOC detected Domain: raw.githubusercontent.com

Indicator of Compromise

XIOC detected Domain: open.apisql.cn

Indicator of Compromise

XIOC detected Domain: docs.apisql.cn

Indicator of Compromise

XIOC detected Domain: github.com

Indicator of Compromise

XIOC detected IP: ::9

Indicator of Compromise

XIOC detected IP: ::8

Indicator of Compromise

XIOC detected IP: b8::

Indicator of Compromise

XIOC detected IP: ::2

Indicator of Compromise

XIOC detected IP: 68::

Indicator of Compromise

XIOC detected URL: https://img.shields.io/npm/v/apisql-mcp.svg)](https://www.npmjs.com/package/apisql-mcp)

Indicator of Compromise

XIOC detected IP: ::a

Indicator of Compromise

XIOC detected IP: 1::

Indicator of Compromise

XIOC detected IP: ::6

Indicator of Compromise

XIOC detected IP: f8::6

Indicator of Compromise

XIOC detected IP: 69::

Indicator of Compromise

XIOC detected IP: ::f

Indicator of Compromise

XIOC detected IP: e0::

Indicator of Compromise

XIOC detected IP: 3338::

Indicator of Compromise

XIOC detected IP: 0::

Indicator of Compromise

XIOC detected IP: 9::

Indicator of Compromise

XIOC detected IP: 8::

Indicator of Compromise

XIOC detected IP: 6::

Indicator of Compromise

XIOC detected IP: 3::

Indicator of Compromise

XIOC detected IP: 4::

Indicator of Compromise

XIOC detected IP: f73::

Indicator of Compromise

XIOC detected IP: 127.0.0.1

Indicator of Compromise

XIOC detected IP: ::

Indicator of Compromise

XIOC detected IP: c::

Indicator of Compromise

XIOC detected IP: ::e

Indicator of Compromise

XIOC detected Email: [email protected]

metadata

HASH-6f0f643599eaa875

metadata

HASH-7e8a9edd6b223e6f

metadata

HASH-321f5719fcf55b7c

metadata

HASH-b7647c2adaffc92c

metadata

HASH-e97c8833321a1c83

metadata

HASH-6f4665382e91ae43

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/13/2026 · Version unknown

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.