HIGH RISK NaN/100

friday-mcp-v2

Unknown developer

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

HIGH Malware Signature

YARA rule match: -credential_env_files

/tmp/extract-401390579fc228c97c60623446be4dd78760e4fc8aa95f2a45f0f67df966de83-3687707930/dist/wordpress-api.js

HIGH Malware Signature

YARA rule match: -postinstall_obfuscation

/tmp/extract-401390579fc228c97c60623446be4dd78760e4fc8aa95f2a45f0f67df966de83-3687707930/dist/wordpress-api.js

HIGH Malware Signature

YARA rule match: -postinstall_file_manipulation

/tmp/extract-401390579fc228c97c60623446be4dd78760e4fc8aa95f2a45f0f67df966de83-3687707930/dist/wordpress-api.js

HIGH Malware Signature

YARA rule match: -postinstall_network_communication

/tmp/extract-401390579fc228c97c60623446be4dd78760e4fc8aa95f2a45f0f67df966de83-3687707930/dist/wordpress-api.js

HIGH Malware Signature

YARA rule match: -postinstall_file_download

/tmp/extract-401390579fc228c97c60623446be4dd78760e4fc8aa95f2a45f0f67df966de83-3687707930/dist/wordpress-api.js

All Findings (94)

View all 94 security findings
Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_registry_modification

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -UsingShellInterpreterWhenExecutingOSCommands

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_registry_modification

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -UsingShellInterpreterWhenExecutingOSCommands

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Malware Signature

YARA rule match: -postinstall_environment_access

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Malware Signature

YARA rule match: -postinstall_environment_access

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: p.id

Indicator of Compromise

XIOC detected Domain: livesessions.map

Indicator of Compromise

XIOC detected URL: http://127.0.0.1:$

Indicator of Compromise

XIOC detected Domain: tabs.map

Indicator of Compromise

XIOC detected Domain: postdata.link

Indicator of Compromise

XIOC detected Domain: conns.map

Indicator of Compromise

XIOC detected Domain: params.search

Indicator of Compromise

XIOC detected Domain: params.page

Indicator of Compromise

XIOC detected Domain: options.store

Indicator of Compromise

XIOC detected Domain: msg.data

Indicator of Compromise

XIOC detected Domain: p.link

Indicator of Compromise

XIOC detected Domain: terms.map

Indicator of Compromise

XIOC detected Domain: t.id

Indicator of Compromise

XIOC detected Domain: job.run

Indicator of Compromise

XIOC detected Domain: delegatedargs.target

Indicator of Compromise

XIOC detected Domain: row.cells.map

Indicator of Compromise

XIOC detected Domain: c.style

Indicator of Compromise

XIOC detected Domain: blocks.map

Indicator of Compromise

XIOC detected Domain: tp.target

Indicator of Compromise

XIOC detected Domain: result.deleted.map

Indicator of Compromise

XIOC detected Domain: m.id

Indicator of Compromise

XIOC detected Domain: m.link

Indicator of Compromise

XIOC detected Domain: posts.map

Indicator of Compromise

XIOC detected Domain: this.ping

Indicator of Compromise

XIOC detected Domain: c.connectededitors.map

Indicator of Compromise

XIOC detected Domain: targetschema.properties

Indicator of Compromise

XIOC detected Domain: result.target

Indicator of Compromise

XIOC detected Domain: debug.polllog.map

Indicator of Compromise

XIOC detected Domain: replacement.new

Indicator of Compromise

XIOC detected Domain: r.preview.map

Indicator of Compromise

XIOC detected Domain: p.new

Indicator of Compromise

XIOC detected Domain: existing.ping

Indicator of Compromise

XIOC detected Domain: connectededitors.map

Indicator of Compromise

XIOC detected Domain: args.site

Indicator of Compromise

XIOC detected Domain: cached.site

Indicator of Compromise

XIOC detected Domain: allconns.map

Indicator of Compromise

XIOC detected Domain: c.name

Indicator of Compromise

XIOC detected Domain: storeconnected.map

Indicator of Compromise

XIOC detected Domain: candidates.map

Indicator of Compromise

XIOC detected Domain: timeouts.global

Indicator of Compromise

XIOC detected Domain: t.name

Indicator of Compromise

XIOC detected Domain: sessions.map

Indicator of Compromise

XIOC detected Domain: probe.ping

Indicator of Compromise

XIOC detected Domain: this.server.off

Indicator of Compromise

XIOC detected Domain: request.id

Indicator of Compromise

XIOC detected Domain: date.now

Indicator of Compromise

XIOC detected Domain: timeouts.read

Indicator of Compromise

XIOC detected Domain: message.id

Indicator of Compromise

XIOC detected Domain: bridge.pid

Indicator of Compromise

XIOC detected Domain: this.store

Indicator of Compromise

XIOC detected Domain: process.pid

Indicator of Compromise

XIOC detected URL: https://example.com)

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server.js-139

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server.js-161

metadata

HASH-b43992d936c58e2a

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/16/2026 · Version unknown

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.