
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@imba_wallet/agent-mcp
Advanced tools
IMBA prepaid agent MCP: USDT TRC-20 deposit and catalog buy with your Ed25519 key. No withdraw, C2C, or convert. Not a ChatGPT money plugin. Tier 1 does not unlock cash-out.
Prepaid agent MCP: USDT TRC-20 deposit and catalog buy (cards, eSIM, gifts) using your Ed25519 key.
Not Partner B2B. Not a ChatGPT money plugin. No withdraw, C2C, convert, Stars,
EVM, BTC, or Altyn. Raising agent_tier does not unlock cash-out.
{
"mcpServers": {
"imba-agent": {
"command": "npx",
"args": ["-y", "@imba_wallet/agent-mcp"],
"env": {
"IMBA_AGENT_CLIENT_ID": "123",
"IMBA_AGENT_PRIVATE_KEY": "-----BEGIN PRIVATE KEY-----\\n...\\n-----END PRIVATE KEY-----"
}
}
}
}
Windows / Cursor: npx.cmd used to break scoped bins. npm 0.1.2 ships agent-mcp with a process-wide AgentApi token cache (do not mint /agent/token per tool). Prefer node mcp/scripts/run-npx-mcp.mjs @imba_wallet/agent-mcp (or run-spend-npx.mjs with gitignored operator secrets).
Remote Streamable HTTP: https://imbawallet.com/mcp/spend with headers
X-IMBA-Agent-Client-Id and X-IMBA-Agent-Private-Key. The private-key header
must be one line (PEM with \n escapes, or base64url). A Wallet JWT or
agent access token is not accepted. IMBA does not host a shared spend wallet.
register_agent is stdio-only.
Always re-fetch get_deposit_address before sending USDT. Pass ext_id on buys.
Optional email on register_agent receives 3-D Secure OTP. Never SMS.
FAQs
IMBA prepaid agent MCP: USDT TRC-20 deposit and catalog buy with your Ed25519 key. No withdraw, C2C as payer, or convert. Humans may C2C to this client_id. Not a ChatGPT money plugin.
The npm package @imba_wallet/agent-mcp receives a total of 23 weekly downloads. As such, @imba_wallet/agent-mcp popularity was classified as not popular.
We found that @imba_wallet/agent-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.