
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
palveron-mcp
Advanced tools
Holding package. This name belongs to Palveron and is held only so that nobody else can claim it. It will never carry functionality.
This is a holding package. This name belongs to Palveron and is held only so that nobody else can claim it. It will never carry functionality.
Running it prints a message to stderr and exits with code 1. Nothing else happens.
A source comment in the public Palveron MCP server once said "Run as: npx palveron-mcp". That line was wrong: "palveron-mcp" is only a bin name inside another package, so npx asks the registry for a package called "palveron-mcp", and until now no such package existed.
The real package is:
@palveron/mcp-server
Documentation: https://docs.palveron.com
Source of this holding package: https://github.com/palveron/npm-name-locks
FAQs
Holding package. This name belongs to Palveron and is held only so that nobody else can claim it. It will never carry functionality.
We found that palveron-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.