
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
MCP server for 350 official-government UAP/UFO records: Pentagon PURSUE Releases 1–4 plus curated archives from 12 nations.
An MCP server (and a live map) for the Pentagon's declassified UAP files.
On July 10, 2026, the U.S. Department of War published PURSUE Release 04 on war.gov/UFO. uap-pulse now bundles all four releases: 334 U.S. records, plus 16 curated official-government cases from 12 nations — 350 records total, spanning 1944–2026.
Official sources only. U.S. PURSUE records are public domain under 17 U.S.C. § 105. The international layer links to official national archives; rights remain with each originating source. No scraped civilian databases. Not affiliated with or endorsed by any government.
🗺️ Live map: https://uap-pulse.vercel.app · 📦 npm: uap-pulse
Your agent can search all 350 records by release, location, agency, era, or type — and pull the direct official source link for each.
Claude Desktop / any MCP client — add to your config:
{
"mcpServers": {
"uap-pulse": { "command": "npx", "args": ["-y", "uap-pulse"] }
}
}
That's it — no API key, no auth, no cost. The data ships with the package.
| Tool | What it does |
|---|---|
search_sightings | Search by release (1–4), free text, agency, type, year range, or location. |
search_nearby | Incidents within a radius (km) of a lat/lng, sorted by distance. |
get_sighting | Full record for one file id (e.g. pursue-042) + the war.gov link. |
full_text_search | Relevance-ranked search across titles, locations, and descriptions. |
notable_cases | Curated historically significant groups with source records. |
hotspots | The locations with the most declassified records. |
stats | Totals + breakdowns by release, agency, file type, and era. |
timeline | Records per decade (or year), 1944 → 2026. |
timeline_data | Per-period records with coordinates for maps and animation. |
Example — "What UAP files mention the Moon?" → search_sightings({ location: "Moon" }) → NASA Gemini/Apollo records with their war.gov links.
Latest release — search_sightings({ release: 4, limit: 100 }) → all 40 files released on July 10, including the 1949 Los Alamos conference transcript, Project Sign records, new sensor videos, and STS-80 images.
A 3D globe of every geolocatable record — points pulse where the sightings cluster, colored by agency, filterable by era (WWII Foo Fighters → the Navy Era). Click a hotspot to read the files and open them on war.gov. Off-world records (Moon, orbit) get their own panel.
Run it locally:
cd site && python3 -m http.server 8080 # then open http://localhost:8080
Or deploy the site/ folder to Vercel (static, no build step).
war.gov CSV is mirrored locally for reproducible builds; coordinates are representative centroids for named locations, maintained in scripts/build_data.py.Rebuild the dataset: npm run data (or python3 scripts/build_data.py).
npm install
npm run build # tsc -> dist/
npm start # run the MCP server over stdio
Code: MIT © David Mosiah (@delx369). Data: U.S. public domain.
FAQs
MCP server for 350 official-government UAP/UFO records: Pentagon PURSUE Releases 1–4 plus curated archives from 12 nations.
The npm package uap-pulse receives a total of 39 weekly downloads. As such, uap-pulse popularity was classified as not popular.
We found that uap-pulse demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.