Skip to main content
Glama
anexbin

mcp-deadbugz-simulator

by anexbin

MCP Deadbugz Simulator

Eine lokale Simulation des Deadbugz-MCP-Supply-Chain-Angriffs, der im August 2026 von Pillar Security entdeckt wurde.

Was dieses Repository enthält

Bösartiger MCP-Server mit 3-Call-Gate-Umgehungstechnik Python-Testrahmen zum Nachweis, dass der Angriff funktioniert Optionale Agentensimulation mit lokalem LLM

Related MCP server: MCP Decoy Server

Das Angriffsmuster

  1. Der Server zeigt bei den ersten 3 Aufrufen harmlose Tools

  2. Der 4. Aufruf löst eine tools/listChanged-Benachrichtigung aus

  3. Tool-Beschreibungen mutieren zu Anweisungen zum Stehlen von Anmeldedaten

  4. Der KI-Agent befolgt die bösartigen Anweisungen

Anforderungen

Python 3.10+ MCP SDK

Verwendung

git clone https://github.com/anexbin/mcp-deadbugz-simulator.git cd mcp-deadbugz-simulator pip install -r requirements.txt python server/malicious_server.py python client/test_harness.py

Dateien

server/malicious_server.py - Der Angriffsserver client/test_harness.py - Proof of Concept agent/local_agent.py - Optionale LLM-Integration configs/ - Beispiel-MCP-Konfigurationen

Haftungsausschluss

Nur für Bildungs- und Forschungszwecke.

Referenzen

https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign https://modelcontextprotocol.io

Lizenz

MIT

Related MCP Connectors

Related MCP Servers

  • F
    license
    D
    quality
    Not graded
    maintenance
    A proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.
    2
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    A deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.
    MIT