{"_id":"mcp-server-supabase","_rev":"2-5561468f1877fd50fc40a0f9dac4364e","name":"mcp-server-supabase","dist-tags":{"latest":"0.0.2"},"versions":{"0.0.1":{"name":"mcp-server-supabase","version":"0.0.1","keywords":["security-research","canary","npx-confusion","bug-bounty"],"license":"MIT","_id":"mcp-server-supabase@0.0.1","maintainers":[{"name":"node-canaries","email":"reacher.dev@proton.me"}],"homepage":"https://github.com/theinfosecguy/npx-canary#readme","bugs":{"url":"https://github.com/theinfosecguy/npx-canary/issues"},"bin":{"mcp-server-supabase":"index.js"},"dist":{"shasum":"53c3f9388bd9cb7fd862b9d6dd1c46f2b7b935c2","tarball":"https://registry.npmjs.org/mcp-server-supabase/-/mcp-server-supabase-0.0.1.tgz","fileCount":3,"integrity":"sha512-BsJPxD8cz1K9NMUPcgPmb6WD6bJwccDiFHZkVNqx2P+GBvC+mfA+AL/G9jzFkWHbOXfMg44XkVCOtQQLE5daSQ==","signatures":[{"sig":"MEUCIQD0m13234QH7uHpNX1NenFya1nH/H+UZxq/Q6lSVi5/ewIgesHKWaIW8zxa1P+J+B1mkiu3Tv79lIFpu5C4iBEK61U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3298},"main":"index.js","gitHead":"a3f48e2f41d1e89e848cd08ecec7032325af0bb3","scripts":{"postinstall":"node index.js"},"_npmUser":{"name":"node-canaries","email":"reacher.dev@proton.me"},"repository":{"url":"git+https://github.com/theinfosecguy/npx-canary.git","type":"git"},"_npmVersion":"11.6.2","description":"Security research canary — not for production use. Part of an authorized bug bounty research project.","directories":{},"_nodeVersion":"25.2.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-server-supabase_0.0.1_1780069671507_0.7518306354114832","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"mcp-server-supabase","version":"0.0.2","description":"Security research canary — not for production use. Part of an authorized bug bounty research project.","main":"index.js","bin":{"mcp-server-supabase":"index.js"},"scripts":{"postinstall":"node index.js"},"repository":{"type":"git","url":"git+https://github.com/theinfosecguy/npx-canary.git"},"license":"MIT","keywords":["security-research","canary","npx-confusion","bug-bounty"],"gitHead":"aa3bb402fbd4cbb5ca0be66cf675106eb797ef2c","_id":"mcp-server-supabase@0.0.2","bugs":{"url":"https://github.com/theinfosecguy/npx-canary/issues"},"homepage":"https://github.com/theinfosecguy/npx-canary#readme","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-zdER7wqGyBt58ep2aaRXQ5rXKo4sNl+7i6sdTw/WN77vz6CHafCFOBmOvrsUVyQT4fPC6A9lqsDBUBuGqtUz3g==","shasum":"412271eb62f468d598731cb71b2e76a2ddf63035","tarball":"https://registry.npmjs.org/mcp-server-supabase/-/mcp-server-supabase-0.0.2.tgz","fileCount":3,"unpackedSize":3303,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIA70cOwTtVUmYvRPslgNQX9E/3WNDsBxQhP9F1+cait9AiEAsv/ehYJpmXekJffj16PDrX9qUXpK1SuKoZ19pvVax7k="}]},"_npmUser":{"name":"node-canaries","email":"reacher.dev@proton.me"},"directories":{},"maintainers":[{"name":"node-canaries","email":"reacher.dev@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server-supabase_0.0.2_1780071710336_0.16887204374251308"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-29T15:47:51.333Z","modified":"2026-05-29T16:21:50.558Z","0.0.1":"2026-05-29T15:47:51.661Z","0.0.2":"2026-05-29T16:21:50.455Z"},"bugs":{"url":"https://github.com/theinfosecguy/npx-canary/issues"},"license":"MIT","homepage":"https://github.com/theinfosecguy/npx-canary#readme","keywords":["security-research","canary","npx-confusion","bug-bounty"],"repository":{"type":"git","url":"git+https://github.com/theinfosecguy/npx-canary.git"},"description":"Security research canary — not for production use. Part of an authorized bug bounty research project.","maintainers":[{"name":"node-canaries","email":"reacher.dev@proton.me"}],"readme":"# mcp-server-supabase — Security Research Canary\n\nThis package is part of an authorized bug bounty research project investigating **npx confusion** — a supply chain attack vector where unclaimed npm package names matching common binary references can be squatted.\n\n## What this package does\n\nOn install or execution, it sends minimal telemetry to a logging endpoint:\n- Timestamp, hostname, working directory, npm user-agent, platform\n- **Nothing sensitive** — no environment variables, file contents, tokens, or keys\n\n## Why it exists\n\nThe unscoped package name `mcp-server-supabase` was unclaimed on npm. The official equivalent (if any) uses a scoped name. AI coding agents and developer tooling commonly invoke `npx mcp-server-supabase`, which resolves to whatever package owns this name on the npm registry. This canary proves that real traffic reaches this name.\n\n## Disclosure\n\nThis is security research. If you received this package unintentionally, it means an AI agent or automated tool resolved `mcp-server-supabase` via npx and the package was publicly available. No malicious action has been taken.\n\n**Questions?** Open an issue: https://github.com/theinfosecguy/npx-canary\n","readmeFilename":"README.md"}