
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@codespar/mcp-bitso
Advanced tools
MCP server for Bitso — Latin American crypto exchange, trading, funding, withdrawals
MCP server for Bitso — Latin American cryptocurrency exchange with trading, orders, and withdrawals
Add to ~/.config/claude/claude_desktop_config.json:
{
"mcpServers": {
"bitso": {
"command": "npx",
"args": ["-y", "@codespar/mcp-bitso"],
"env": {
"BITSO_API_KEY": "your-key",
"BITSO_API_SECRET": "your-secret"
}
}
}
}
claude mcp add bitso -- npx @codespar/mcp-bitso
Add to .cursor/mcp.json or .vscode/mcp.json:
{
"servers": {
"bitso": {
"command": "npx",
"args": ["-y", "@codespar/mcp-bitso"],
"env": {
"BITSO_API_KEY": "your-key",
"BITSO_API_SECRET": "your-secret"
}
}
}
}
| Tool | Purpose |
|---|---|
get_ticker | Get ticker data for a trading pair (price, volume, VWAP, etc.) |
list_orderbook | Get order book (bids and asks) for a trading pair |
create_order | Create a buy or sell order |
get_order | Get order details by ID |
cancel_order | Cancel an open order |
list_orders | List orders with optional filters |
get_balances | Get account balances for all assets |
list_trades | List executed trades for an order book |
list_funding_sources | List available funding sources (bank accounts, etc.) |
create_withdrawal | Create a withdrawal request (crypto or fiat) |
list_ledger | List account ledger entries (trades, fees, fundings, withdrawals) |
list_open_orders | List currently open orders for the authenticated user |
lookup_order | Look up one or more orders by origin_id (client_id) |
cancel_all_orders | Cancel all open orders for the authenticated user |
list_fundings | List account fundings (deposits) |
list_withdrawals | List account withdrawals |
get_withdrawal | Retrieve a specific withdrawal by its ID |
list_fees | List applicable fees for the authenticated user across trading pairs |
get_account_status | Retrieve account KYC and verification status (tier, limits, required docs) |
list_funding_destinations | Get funding destination details (address/CLABE) for a given currency |
Bitso uses HMAC-SHA256 signed requests with an API key and secret.
Bitso provides a developer sandbox via the developer account.
| Variable | Required | Description |
|---|---|---|
BITSO_API_KEY | Yes | API key from Bitso |
BITSO_API_SECRET | Yes | API secret for HMAC signature |
get_account_status — Get account verification statuslist_currencies — List available cryptocurrenciescreate_spei_withdrawal — Create a SPEI (Mexican bank) withdrawalget_phone_number — Get phone number associated with accountlist_open_orders — List all open ordersrecurring_orders — Create and manage recurring buy/sell ordersadvanced_orders — Advanced order types (OCO, trailing stop)Want to contribute? Open a PR or request a tool.
Need governance, budget limits, and audit trails for agent payments? CodeSpar Enterprise adds policy engine, payment routing, and compliance templates on top of these MCP servers.
MIT
FAQs
MCP server for Bitso — Latin American crypto exchange, trading, funding, withdrawals
The npm package @codespar/mcp-bitso receives a total of 69 weekly downloads. As such, @codespar/mcp-bitso popularity was classified as not popular.
We found that @codespar/mcp-bitso demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.