The MCP supply chain: 71% of public packages have one maintainer
A fresh threat dataset shows the Model Context Protocol package ecosystem has 973 packages on npm, 71% with a single maintainer, and 9 of 11 registries failed to detect malicious uploads.