
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@axionquant/mcp
Advanced tools
A Model Context Protocol (MCP) server that provides LLM access to the Axion financial data API endpoints.
This MCP server exposes all Axion product API endpoints as LLM-accessible tools, enabling AI assistants to query financial data including stocks, cryptocurrencies, forex, futures, indices, ETFs, credit ratings, ESG data, and supply chain information.
cd server/mcp-server
npm install
cp .env.example .env
Edit .env and set:
API_KEY: Your API authentication key (if required)npm start
Add this to your Claude Desktop configuration file:
MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"axion-financial-data": {
"command": "node",
"args": ["/absolute/path/to/axion/server/mcp-server/index.js"],
"env": {
"API_KEY": "your_api_key_here"
}
}
}
}
The server uses stdio transport, making it compatible with any MCP client. Configure according to your client's documentation.
get_stock_tickers - Get all stock tickers with optional country/exchange filteringget_stock_ticker_info - Get detailed info for a specific stockget_stock_prices - Get historical price data for a stockget_crypto_tickers - Get all crypto tickersget_crypto_ticker_info - Get detailed info for a specific cryptoget_crypto_prices - Get historical price data for a cryptoget_forex_tickers - Get all forex pairsget_forex_ticker_info - Get detailed info for a forex pairget_forex_prices - Get historical price data for a forex pairget_futures_tickers - Get all futures tickersget_futures_ticker_info - Get detailed info for a futures contractget_futures_prices - Get historical price data for a futures contractget_indices_tickers - Get all market indicesget_indices_ticker_info - Get detailed info for an indexget_indices_prices - Get historical price data for an indexget_etf_fund_data - Get comprehensive fund data including weights and regionsget_etf_holdings - Get detailed holdings informationget_etf_exposure - Get exposure analysissearch_credit_entities - Search S&P credit rating databaseget_credit_ratings - Get credit ratings for a specific entityget_esg_data - Get ESG (Environmental, Social, Governance) data for a tickerget_company_customers - Get a company's customersget_company_peers - Get peer companies (competitors)get_company_suppliers - Get a company's suppliersOnce configured with an LLM client like Claude Desktop, you can ask:
The MCP server acts as a bridge between LLMs and your Axion REST API:
LLM (Claude, etc.) <--> MCP Server <--> Axion REST API
All API requests are proxied through the MCP server, which translates LLM tool calls into REST API requests.
server/mcp-server/
├── index.js # Main MCP server implementation
├── package.json # Node.js dependencies
├── .env.example # Environment variable template
└── README.md # This file
To add new API endpoints:
ListToolsRequestSchema handlerCallToolRequestSchema handlernpm install.env file exists and has correct valuesMIT
FAQs
Official Model Context Protocol (MCP) server for the AxionQuant financial data API. Give Claude, GPT, and other LLMs real-time and historical stock, crypto, forex, futures, and economic data, plus SEC filings and company financials.
The npm package @axionquant/mcp receives a total of 41 weekly downloads. As such, @axionquant/mcp popularity was classified as not popular.
We found that @axionquant/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.