
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
google-researcher-mcp
Advanced tools
DEPRECATED — Use web-researcher-mcp instead. See https://github.com/zoharbabin/web-researcher-mcp
⚠️ This project has been superseded by
web-researcher-mcp.The new version is a complete rewrite in Go that resolves all open issues, adds multiple search providers (Brave, Serper, SearXNG), and ships as a single static binary — no Node.js or npm required.
Quick summary:
google-researcher entry from your MCP client configgo install, Docker, or download from Releases)web-researcher entry to your MCP configYour existing GOOGLE_CUSTOM_SEARCH_API_KEY and GOOGLE_CUSTOM_SEARCH_ID work without changes.
| Open Issue | Resolution in web-researcher-mcp |
|---|---|
| #108 — Orphan detection fails via npx | Go binary has native process lifecycle (EOF/SIGPIPE) — no npm wrapper |
| #107 — Google discontinuing 'entire web' search | Supports 4 providers: Brave, Serper, SearXNG + Google PSE for lenses |
| #55 — Support alternative search engines | Built-in Brave, Serper, and SearXNG support |
| #72 — Add Redis caching | Hybrid 3-tier cache: memory + AES-encrypted disk + optional Redis |
| #40 — Split server.ts into modules | Fully modular Go architecture (one package per concern) |
docker pull zoharbabin/web-researcher-mcp:latestThis repository is archived and read-only. No further updates will be made here.
FAQs
DEPRECATED — Use web-researcher-mcp instead. See https://github.com/zoharbabin/web-researcher-mcp
The npm package google-researcher-mcp receives a total of 0 weekly downloads. As such, google-researcher-mcp popularity was classified as not popular.
We found that google-researcher-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.