
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@anaxer/mcp
Advanced tools
Official MCP server for Anaxer — query Solana DEX data from Claude Desktop, Claude Code, Cursor, and other MCP hosts.
@anaxer/mcpOfficial MCP server for the Anaxer Solana real-time data API. Add a few lines to Claude Desktop, Claude Code, or Cursor and the assistant can call typed tools over your API key — prices, metadata, creations, graduations, and a bounded live stream tail.
Requires Node ≥ 20. This package wraps @anaxer/sdk;
it adds no gateway or wire behavior.
npx -y @anaxer/mcp
Set ANAXER_API_KEY in the MCP host config (never pass the key as a tool argument).
{
"mcpServers": {
"anaxer": {
"command": "npx",
"args": ["-y", "@anaxer/mcp"],
"env": {
"ANAXER_API_KEY": "sk_live_…"
}
}
}
}
Optional:
| Env | Default | Purpose |
|---|---|---|
ANAXER_BASE_URL | https://api.anaxer.com | REST base (local gateway: http://localhost:3010) |
ANAXER_WS_URL | derived from base → …/v1/stream | Override WebSocket URL |
| Tool | What it answers |
|---|---|
get_token_metadata | Name/symbol/supply/socials for one mint |
get_tokens_metadata | Batch metadata (≤50 mints) |
get_token_price | Latest USD + SOL price / market cap for one mint |
get_token_prices | Batch prices (≤50 mints) |
list_token_trades | One page of swaps for a mint (either leg; optional solOnly; quote :mint rejected) |
list_creations | One page of recent launches |
list_graduations | One page of recent graduations |
get_launchpad_stats | Aggregate launchpad stats over a window |
tail_stream | Bounded live WS batch (trades / creations / graduations / prices) |
List tools default to limit: 20 (max 200) to conserve model context. Paginate by calling
again with cursor set to the previous next; stop when next is null.
Spelling: REST list tools take a singular source string. tail_stream filters use a
sources array (WebSocket filter shape).
tail_stream capsmaxEvents — default 20, cap 100timeoutMs — default 10_000, cap 30_000Per-channel filter keys:
trades: sources, mints, wallets, minVolumeUsd, maxVolumeUsd, solOnly
(quote assets SOL/USDC/USDT rejected in mints — use solOnly: true for SOL pairs)creations: sources, enriched, excludeMayhemgraduations: sources, excludeMayhem, minLiquiditySolprices: sources, mintsThese are intentional, not bugs:
tail_stream("transfers") and no list_programs (same as @anaxer/sdk v1)tail_stream. REST tools fail per call and recover as soon as you
fix ANAXER_API_KEY. WebSocket unauthorized is terminal for the shared socket —
restart the MCP server process (reload the host / re-run npx @anaxer/mcp) after
fixing the key.subscription_limit. Each open tail_stream holds one plan subscription until it
returns. Overlapping tails (or a leaked subscription) on free/low plans can hit the
cap. The server always close()s in finally; hosts normally serialize tool calls, so
this is rare.MIT
FAQs
Official MCP server for Anaxer — query Solana DEX data from Claude Desktop, Claude Code, Cursor, and other MCP hosts.
The npm package @anaxer/mcp receives a total of 14 weekly downloads. As such, @anaxer/mcp popularity was classified as not popular.
We found that @anaxer/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.