T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Mutable npm Dependency Executes with Wallet Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16-28
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: HighVulnerable Code
bash mcporter config add onlyswaps --command "npx -y @onlyswaps/mcp-server@latest stdio" --transport stdiojson { "mcpServers": { "onlyswaps": { "command": "npx", "args": ["-y", "@onlyswaps/mcp-server@latest", "stdio"] } } }Technical Analysis
The configuration uses
npx -yto download and execute the mutablelatestrelease of@onlyswaps/mcp-server. The-yoption suppresses interactive confirmation, while the@latesttag can resolve to different package contents at different times. No exact version, lockfile, integrity hash, or locally auditable implementation is supplied by the project.The downloaded MCP server is subsequently expected to operate with a cryptocurrency wallet private key and exposes capabilities for token transfers, swaps, and token approvals. Consequently, compromise of the npm account, package publication pipeline, dependency graph, or a future package release could place attacker-controlled code in a process with access to wallet credentials and transaction authority.
Attack Path
- An attacker compromises the npm package, its maintainer account, publication pipeline, or a transitive dependency.
- The attacker publishes a malicious release under the package's
latesttag. - A user follows the documented setup command.
npx -yretrieves and executes the malicious release without displaying an installation confirmation.- The user invokes a wallet operation and supplies
PRIVATE_KEYto the MCP server process. - The malicious process reads or exfiltrates the key, alters transaction parameters, or submits unauthorized approvals and transfers.
- The attacker uses the acquired signing authority or approvals to steal wallet ass ...[truncated 405 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Use a lockfile and verify package integrity hashes before execution.
- Remove automatic
-yinstallation from security-sensitive deployment instructions. - Vendor or publish the corresponding source code so credential handling and transaction construction can be audited.
- Run the MCP server in a sandbox with restricted filesystem and network access.
- Use a dedicated, low-value wallet rather than a primary wallet.
- Require explicit review and confirmation of destination addresses, token amounts, spender approvals, fees, and chain IDs before signing.
- Establish a controlled dependency-update process that requires code review and security testing before changing the pinned version.
- Replace
