
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
MCP server to support Astro project development, inspired by antfu's nuxt-mcp.
[!IMPORTANT] This package is experimental and unstable. Proceed with caution when using it.
astro-mcp
aims to help models understand your Astro project better, by providing them with information that cannot be easily accessed just by looking at the project files, such as:
In your Astro project directory, run the following command:
npx astro add astro-mcp
First, install the astro-mcp
package:
npm install astro-mcp
Then, add the astro-mcp
integration to your Astro config:
import { defineConfig } from "astro/config";
import mcp from "astro-mcp";
export default defineConfig({
integrations: [mcp()],
});
After installing the integration, the MCP server will be available at http://localhost:4321/__mcp/sse. To connect, create an empty configuration file in the appropriate location for your editor or tool:
Editor/Tool | Configuration File |
---|---|
VSCode | .vscode/mcp.json |
Cursor | .cursor/mcp.json |
Windsurf | ~/.codeium/windsurf/mcp_config.json |
Claude Code | .mcp.json |
astro-mcp
will automatically update the file when the Astro server starts.
astro-mcp
provides a hook called mcp:setup
that other integrations can use to extend the MCP server. This is useful if you want to add custom tools to the MCP server.
export default function createExampleIntegration(): AstroIntegration {
return {
name: "example-integration",
hooks: {
"mcp:setup": async ({ mcp }) => {
mcp.tool("add", { a: z.number(), b: z.number() }, async ({ a, b }) => ({
content: [{ type: "text", text: String(a + b) }],
}));
},
},
};
}
get-astro-config
: Get the Astro config object containing comprehensive project settings including file paths (root, src, public, output directories), site URL, build options, server settings, enabled integrations, markdown processing configuration, image handling, Vite plugins, security settings, and experimental features
list-astro-routes
: List detailed routing information from your Astro project, including all routes with their file entrypoints, URL patterns, dynamic parameters, pre-rendering status, and route types. Optionally filter by type to focus on specific route categories
type
(string, optional): redirect
, page
, endpoint
, or fallback
get-astro-server-address
: Get the current network address, IP protocol family, and port number of the running Astro development server
list-astro-integrations
: List all Astro integrations available in the ecosystem
get-astro-integration
: Get detailed metadata about a specific Astro integration, including its name, description, categories, repository links, npm information, related website links, official status, and download statistics
name
(string): The name of the Astro integration to get information aboutsearch-astro-docs
: Search the Astro documentation for specific topics, concepts, or features. Returns relevant documentation snippets that match your query
query
(string): The query to search forget-astro-changes
: Get the changelog of the Astro-related packages
packageName
(string): The name of the Astro-related package to get the changelog forvite-plugin-mcp
get-vite-config
: Get the Vite config digest, including the root, resolve, plugins, and environment names
get-vite-module-info
: Get graph information of a module, including importers, imported modules, and compiled result
filepath
(string): The absolute filepath of the moduleFAQs
MCP server to support Astro project development
The npm package astro-mcp receives a total of 202 weekly downloads. As such, astro-mcp popularity was classified as not popular.
We found that astro-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.