
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@qmailing/mcp-server
Advanced tools
Model Context Protocol server for qmailing — lets AI agents (Claude Desktop, Cursor, Continue, ...) read and modify mailboxes, custom domains, and email through the qmailing public API.
Two ways to plug an AI agent into qmailing — pick the one that matches your client.
| Client | Recommended setup |
|---|---|
| Claude.ai (web / mobile) | Custom Connector — one URL, no token, OAuth handles auth |
| Claude Desktop, Cursor, Continue, Zed, custom CLIs | @qmailing/mcp-server — npm package + API token |
The two paths give the same tool surface — qmailing_list_mailboxes,
qmailing_send_email, etc. They differ only in how the client
authenticates: OAuth flow (browser) vs static bearer token (CLI / config).
Works with the Claude.ai web app and Claude mobile. No package install, no token management — the OAuth flow brokers per-grant scope consent and rotates refresh tokens automatically.
https://qmailing.com/mcp
Same vocabulary as the API token scopes below. You consent to each one separately on first connection; granted scopes persist across re-grants until you revoke.
For clients that don't speak OAuth Custom Connectors yet — Claude Desktop, Cursor, Continue, Zed, and any CLI MCP client.
Sign in at https://qmailing.com.
Go to Settings → Developers.
Click New token, give it a label (e.g. "Claude Desktop"), pick the scopes you want the agent to have, and copy the qm_live_… value when it's shown.
The token only appears once. If you lose it, generate a fresh one.
The package is published on the public npm registry under the beta tag — npx pulls it on first run, no manual checkout required.
Edit claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"qmailing": {
"command": "npx",
"args": ["-y", "@qmailing/mcp-server"],
"env": {
"QMAILING_API_TOKEN": "qm_live_your_token_here"
}
}
}
}
Pin a specific version (e.g. @qmailing/mcp-server@0.1.1) if you don't want auto-upgrades.
claude mcp add qmailing -- npx -y @qmailing/mcp-server
# Add the env var separately or supply via a wrapper script.
Any MCP client that supports stdio servers takes the same command + args + env shape. Restart the client after editing its config — the qmailing tools appear in the tools menu (the wrench icon in Claude Desktop, similar in others).
Contributors can run from a checkout instead of npm. Build + point the client at the absolute path:
cd qmailing-web/mcp
npm install
npm run build # produces dist/server.js
{
"mcpServers": {
"qmailing": {
"command": "node",
"args": ["/absolute/path/to/qmailing-web/mcp/dist/server.js"],
"env": { "QMAILING_API_TOKEN": "qm_live_your_token_here" }
}
}
}
| Tool | What it does | Required scope |
|---|---|---|
qmailing_list_mailboxes | List every mailbox on the account | mailboxes:read |
qmailing_get_mailbox | Fetch one mailbox by id | mailboxes:read |
qmailing_create_mailbox | Create a new mailbox under qmailing.com or a verified custom domain | mailboxes:write |
qmailing_list_domains | List custom domains and verification state | domains:read |
qmailing_get_dns_records | DNS-records checklist for one domain | domains:read |
| Env var | Default | Purpose |
|---|---|---|
QMAILING_API_TOKEN | required | Bearer token from /settings/developers |
QMAILING_API_URL | https://qmailing.com | Override for self-hosted / staging deployments |
The package source is maintained in the qmailing monorepo. To work on it
locally with a checkout, install deps inside the mcp/ directory and
build:
cd mcp
npm install
npm run build
QMAILING_API_TOKEN=qm_live_test_token npm start
For bug reports or questions, reach us through the contact form at qmailing.com/contact.
MIT
FAQs
Model Context Protocol server for QMailing — lets AI agents (Claude Desktop, Cursor, Continue, ...) read and modify mailboxes, custom domains, and email through the QMailing public API.
The npm package @qmailing/mcp-server receives a total of 69 weekly downloads. As such, @qmailing/mcp-server popularity was classified as not popular.
We found that @qmailing/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.