
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
Email verification for AI agents. One call returns send, hold or kill with the reason. Free DNS tier runs locally; the hosted SMTP probe is 9 USD per 10,000 checks. CLI + MCP server.
Email verification for AI agents. One call returns send, hold or kill
with the reason. The DNS tier is free and runs on your machine; the hosted
SMTP probe is 9 USD per 10,000 checks, 100 free at signup.
npx mxprobe check hello@example.com ops@example.org # free, local, no key
npx mxprobe signup you@company.com # a key by API, 100 free checks, saved to ~/.config/mxprobe
npx mxprobe check --hosted hello@example.com # DNS kills stay local; survivors go to the mailbox probe
npx mxprobe balance
npx mxprobe buy # a Stripe link: 9 USD per 10,000, credits never expire
npx mxprobe mcp # the MCP server on stdio
claude mcp add mxprobe -- npx -y mxprobe mcp
One click: Cursor · VS Code ·
LM Studio. In Claude Code, as a plugin:
/plugin marketplace add andrewchmr/mxprobe, then /plugin install mxprobe@mxprobe.
Any client: {"mcpServers":{"mxprobe":{"command":"npx","args":["-y","mxprobe","mcp"]}}}
Tools: verify_email, verify_batch, signup, balance, buy_credits.
With a key configured, verify_* probe the mailbox on the hosted tier; without
one they run the free DNS tier. Set MXPROBE_API_KEY to use a key from the
environment.
{
"email": "hello@example.com",
"action": "send",
"verdict": "OK",
"reason": "mailbox accepted by aspmx.l.google.com",
"checks": { "syntax": true, "mx": "aspmx.l.google.com", "smtp": "accepted", "catch_all": false }
}
send: the mail server accepted the mailbox.hold: send only with a fallback in hand. A catch-all, a forwarder, a
greylist, or a server that refused the probe rather than the mailbox.kill: never send. No mail server, or the mailbox does not exist.import { createClient, checkEmails } from "mxprobe";
const client = createClient({ apiKey: process.env.MXPROBE_API_KEY });
const { results, summary } = await checkEmails(["a@b.com"], { hosted: true, client });
Typed: Client, CheckOptions, CheckOutput and the response types come
with the package; results is VerifyResult[] from mxprobe-core.
Docs: https://mxprobe.dev. Source: https://github.com/andrewchmr/mxprobe. MIT.
FAQs
Email verification for AI agents. One call returns send, hold or kill with the reason. Free DNS tier runs locally; the hosted SMTP probe is 9 USD per 10,000 checks. CLI + MCP server.
The npm package mxprobe receives a total of 38 weekly downloads. As such, mxprobe popularity was classified as not popular.
We found that mxprobe demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.