{"_id":"mcp-server-git","_rev":"2-f3a6843fe0e0208481fae441d34988af","name":"mcp-server-git","dist-tags":{"latest":"0.0.2"},"versions":{"0.0.1":{"name":"mcp-server-git","version":"0.0.1","keywords":["security-research","canary","npx-confusion","bug-bounty"],"license":"MIT","_id":"mcp-server-git@0.0.1","maintainers":[{"name":"node-canaries","email":"reacher.dev@proton.me"}],"homepage":"https://github.com/theinfosecguy/npx-canary#readme","bugs":{"url":"https://github.com/theinfosecguy/npx-canary/issues"},"bin":{"mcp-server-git":"index.js"},"dist":{"shasum":"15ae727f57d27ba2136c6a9cfd09f9bb389dacca","tarball":"https://registry.npmjs.org/mcp-server-git/-/mcp-server-git-0.0.1.tgz","fileCount":3,"integrity":"sha512-ceAU3W3ZYBI4zq8mqNajWYt0+7PHwI4QLWw1xdVIOe8EjMpNxtJZsT1XarIaNrZxLi1eaAo0+4WH8rO/PJwdOQ==","signatures":[{"sig":"MEYCIQDavUgzEakyK5/q1x3Ccbc0k0guWryau1LRg04KJf5toAIhAMSz50H+Pw40LbHMhZAV0kp9b6T7jHGm21jBqbGGvSxy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3263},"main":"index.js","gitHead":"a3f48e2f41d1e89e848cd08ecec7032325af0bb3","scripts":{"postinstall":"node index.js"},"_npmUser":{"name":"node-canaries","email":"reacher.dev@proton.me"},"repository":{"url":"git+https://github.com/theinfosecguy/npx-canary.git","type":"git"},"_npmVersion":"11.6.2","description":"Security research canary — not for production use. Part of an authorized bug bounty research project.","directories":{},"_nodeVersion":"25.2.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-server-git_0.0.1_1780069657147_0.3018377367299361","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"mcp-server-git","version":"0.0.2","description":"Security research canary — not for production use. Part of an authorized bug bounty research project.","main":"index.js","bin":{"mcp-server-git":"index.js"},"scripts":{"postinstall":"node index.js"},"repository":{"type":"git","url":"git+https://github.com/theinfosecguy/npx-canary.git"},"license":"MIT","keywords":["security-research","canary","npx-confusion","bug-bounty"],"gitHead":"aa3bb402fbd4cbb5ca0be66cf675106eb797ef2c","_id":"mcp-server-git@0.0.2","bugs":{"url":"https://github.com/theinfosecguy/npx-canary/issues"},"homepage":"https://github.com/theinfosecguy/npx-canary#readme","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-fLoB/yIRDnNsSbxFdzBzxTxK8k156loAQMotUoHnNhh8eq3gqSIkeqYMYPZuojT9uq/EEljpFuqQ9gOS3I9pow==","shasum":"53ca9ee3b98f7356e87220674c72537c728627ae","tarball":"https://registry.npmjs.org/mcp-server-git/-/mcp-server-git-0.0.2.tgz","fileCount":3,"unpackedSize":3268,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBQGpDkkeNLIyjOi7nR84F+yK6Ql+XCkLJ/Ky8h4wEQlAiAbYbJ6iRY19LyaHwI6lag8Jxi+WFMSeCIWFyRlESlIaQ=="}]},"_npmUser":{"name":"node-canaries","email":"reacher.dev@proton.me"},"directories":{},"maintainers":[{"name":"node-canaries","email":"reacher.dev@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server-git_0.0.2_1780071689696_0.5741303733163188"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-29T15:47:37.036Z","modified":"2026-05-29T16:21:30.016Z","0.0.1":"2026-05-29T15:47:37.297Z","0.0.2":"2026-05-29T16:21:29.876Z"},"bugs":{"url":"https://github.com/theinfosecguy/npx-canary/issues"},"license":"MIT","homepage":"https://github.com/theinfosecguy/npx-canary#readme","keywords":["security-research","canary","npx-confusion","bug-bounty"],"repository":{"type":"git","url":"git+https://github.com/theinfosecguy/npx-canary.git"},"description":"Security research canary — not for production use. Part of an authorized bug bounty research project.","maintainers":[{"name":"node-canaries","email":"reacher.dev@proton.me"}],"readme":"# mcp-server-git — Security Research Canary\n\nThis package is part of an authorized bug bounty research project investigating **npx confusion** — a supply chain attack vector where unclaimed npm package names matching common binary references can be squatted.\n\n## What this package does\n\nOn install or execution, it sends minimal telemetry to a logging endpoint:\n- Timestamp, hostname, working directory, npm user-agent, platform\n- **Nothing sensitive** — no environment variables, file contents, tokens, or keys\n\n## Why it exists\n\nThe unscoped package name `mcp-server-git` was unclaimed on npm. The official equivalent (if any) uses a scoped name. AI coding agents and developer tooling commonly invoke `npx mcp-server-git`, which resolves to whatever package owns this name on the npm registry. This canary proves that real traffic reaches this name.\n\n## Disclosure\n\nThis is security research. If you received this package unintentionally, it means an AI agent or automated tool resolved `mcp-server-git` via npx and the package was publicly available. No malicious action has been taken.\n\n**Questions?** Open an issue: https://github.com/theinfosecguy/npx-canary\n","readmeFilename":"README.md"}