
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@pasteapp/mcp
Advanced tools
Local MCP server bridge for Paste — give Claude Desktop, Claude Code, Cursor, Codex, and other AI tools access to your Mac clipboard history and pinboards.
Local MCP server for Paste. Give Claude, Codex, Cursor, and other AI tools access to your Mac's clipboard history and pinboards — without anything leaving your device.
Your assistant can search your clipboard items, pull one into context, or save its output to a pinboard.
Use add-mcp to connect Paste to all your installed AI apps:
npx add-mcp @pasteapp/mcp
The first time an app uses Paste, it'll ask you to authenticate and allow access.
Alternatively, connect Paste to each app manually:
claude mcp add paste -- npx -y @pasteapp/mcp
codex mcp add paste -- npx -y @pasteapp/mcp
You can also connect any app right inside Paste. Open Settings → MCP & AI Tools, click Connect AI Tool, and choose your app — Paste does the rest.

Paste MCP runs locally on your Mac. Your clipboard items only go to the AI apps you approve. You can revoke access anytime.
The AI tool says Paste isn't available. Make sure Paste is running and MCP is enabled in Settings → MCP & AI Tools.
Tools don't show up after connecting. Fully quit and reopen your AI app so it relaunches the server.
npx errors or "command not found".
Confirm Node.js 18+ is installed: node --version.
Issues and pull requests welcome — see the issue tracker.
FAQs
Local MCP server bridge for Paste — give Claude Desktop, Claude Code, Cursor, Codex, and other AI tools access to your Mac clipboard history and pinboards.
The npm package @pasteapp/mcp receives a total of 49 weekly downloads. As such, @pasteapp/mcp popularity was classified as not popular.
We found that @pasteapp/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.