mexc-futures
Audited by Socket on Sep 18, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The core capability matches the stated purpose of MEXC futures trading, and the requested exchange credentials are broadly proportionate. However, it enables high-impact autonomous financial actions, contains a misleading 'No KYC' claim contradicted by official docs, and omits implementation details needed to verify whether credentials and trade data go only to official MEXC endpoints and a legitimate local database.
The fragment is a legitimate MEXC futures trading command handler, not apparent malware. It intentionally uses API credentials to query and modify a trading account and records activity in a database. The main risks are high-impact financial actions, potentially missing authorization controls in this module, and permissive numeric parsing. Review the imported exchange and database implementations and the command authorization layer before deployment.