
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
aproxproxy-mcp
Advanced tools
MCP server for AproxPay residential proxy — pay-per-request and session passes via x402 (optional exit country)
MCP server for AproxPay — residential proxy built for autonomous AI agents, paid with x402 (USDC on Base).
| Tool | Pays | Description |
|---|---|---|
list_countries | free | ISO exit countries accepted by create_session region |
proxy_get | ~$0.003 | Fetch a URL through residential IP (2MB cap). Billed per forward; returns origin status from X-Target-Status (use /v1/proxy/large for up to 5MB) |
create_session | tiered | Buy a session pass + ephemeral CONNECT credentials; tier: entry ($0.05 / 15MB / 30m), heavy ($0.50 / 200MB / 60m), gb ($2.50 / 1GB / ≤120m dedicated); optional region |
extend_session | ~$0.15 | Top up +30 min / +50MB without changing exit IP or country (pooled sessions only; gb returns 409) |
close_session | free | Invalidate credentials early (no automatic refund; upstream sub-user is not revoked) |
list_countries (free) → curated ISO 3166-1 alpha-2 codes (OFAC codes excluded).create_session with tier + region: "us" (or another code) — no surcharge; the CONNECT gateway pins DataImpulse cr.{code} for the whole session.extend_session keeps the same country and sticky exit IP.proxy_get still accepts region for forward-compat, but product A does not enforce it yet — use a session pass when you need a country-pinned IP.
Every request to the proxy API includes X-Client-Source: mcp for channel attribution.
Add to your Claude Desktop MCP config (claude_desktop_config.json):
{
"mcpServers": {
"aproxproxy": {
"command": "npx",
"args": ["-y", "aproxproxy-mcp"],
"env": {
"APROXPROXY_PRIVATE_KEY": "0xYOUR_BUYER_PRIVATE_KEY",
"APROXPROXY_BASE_URL": "https://proxy.aproxpay.com"
}
}
}
}
Then ask Claude to call list_countries, or create_session with tier: "entry" and region: "us", or proxy_get with url: "https://example.com".
| Variable | Required | Default | Notes |
|---|---|---|---|
APROXPROXY_PRIVATE_KEY | yes | — | 0x + 64 hex chars. Signs x402 payments. Never commit. |
APROXPROXY_BASE_URL | no | https://proxy.aproxpay.com | Point at local proxy for testnet: http://localhost:8080 |
APROXPROXY_HTTP_PORT | no | 3100 | Only used with --http |
APROXPROXY_HTTP_HOST | no | 127.0.0.1 | Only used with --http |
APROXPROXY_BASE_URL=http://localhost:8080 and the testnet private key.list_countries, then create_session with a tier and optional region, or proxy_get.npx -y aproxproxy-mcpnpx -y aproxproxy-mcp --http listens on http://127.0.0.1:3100/mcpRemote HTTP is self-hosted only. The payment private key must stay on the operator's machine. AproxPay does not host a shared remote MCP endpoint (that would be custodial).
close_session does not refund: x402 exact-scheme settlements are irreversible; manual refunds go through admin.MIT
FAQs
MCP server for AproxPay residential proxy — pay-per-request and session passes via x402 (optional exit country)
The npm package aproxproxy-mcp receives a total of 118 weekly downloads. As such, aproxproxy-mcp popularity was classified as not popular.
We found that aproxproxy-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.