
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@stophy/mcp
Advanced tools
Public web data for AI agents. Connects your MCP app to the hosted Stophy server.
Give your AI agent public web data: web search, YouTube, Reddit, TikTok, Instagram, LinkedIn, maps, shopping, jobs, real estate, finance, and more. Your agent reaches every Stophy endpoint through three MCP tools.
Most apps can connect to the hosted server directly. There is nothing to install.
| URL | How you connect | What your agent can use |
|---|---|---|
https://api.stophy.dev/mcp | No key | The free endpoints: web search, YouTube search, and YouTube transcripts |
https://api.stophy.dev/mcp | Authorization: Bearer <key> header | Every endpoint |
https://api.stophy.dev/mcp-oauth | Sign in with your browser | Every endpoint |
Get an API key at stophy.dev/signup.
To sign in with your browser, add the server, then run /mcp and choose Authenticate:
claude mcp add --transport http stophy https://api.stophy.dev/mcp-oauth
To use an API key:
claude mcp add --transport http stophy https://api.stophy.dev/mcp --header "Authorization: Bearer <key>"
To start without a key:
claude mcp add --transport http stophy https://api.stophy.dev/mcp
To use the key in your STOPHY_API_KEY environment variable:
codex mcp add stophy --url https://api.stophy.dev/mcp --bearer-token-env-var STOPHY_API_KEY
To sign in with your browser instead, add the sign-in URL, then log in:
codex mcp add stophy --url https://api.stophy.dev/mcp-oauth
codex mcp login stophy
Add this to .cursor/mcp.json:
{
"mcpServers": {
"stophy": {
"url": "https://api.stophy.dev/mcp",
"headers": { "Authorization": "Bearer <key>" }
}
}
}
To start without a key, leave out headers.
Some apps can only start a local MCP server. For those, use this package. It runs on your computer and passes every request to the hosted server, so it always has the same tools.
npx -y @stophy/mcp
With STOPHY_API_KEY set, your agent can use every endpoint. Without it, your agent gets the free endpoints.
Add this to claude_desktop_config.json, then restart Claude Desktop:
{
"mcpServers": {
"stophy": {
"command": "npx",
"args": ["-y", "@stophy/mcp"],
"env": { "STOPHY_API_KEY": "<key>" }
}
}
}
To start without a key, leave out env.
The package needs Node.js 18 or later.
| Variable | What it does |
|---|---|
STOPHY_API_KEY | Your Stophy API key. Optional. |
STOPHY_MCP_URL | The server to connect to. The default is https://api.stophy.dev/mcp. |
| Tool | What it does |
|---|---|
stophy_search_endpoints | Finds the endpoint for a task, with its cost |
stophy_describe_endpoint | Shows the input an endpoint takes and whether it has more pages |
stophy_call | Runs an endpoint and returns markdown, or JSON when you ask for it |
Your agent usually searches, then describes, then calls. Each result says how many credits it used.
MIT
FAQs
One API for live, structured web data. REST, MCP, SDK and CLI.
The npm package @stophy/mcp receives a total of 885 weekly downloads. As such, @stophy/mcp popularity was classified as not popular.
We found that @stophy/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.