Skip to main content
Glama
anexbin

mcp-deadbugz-simulator

by anexbin

MCP Deadbugz Simulator

2026年8月にPillar Securityが発見したDeadbugz MCPサプライチェーン攻撃のローカルシミュレーションです。

このリポジトリの内容

3コールゲート回避テクニックを備えた悪意のあるMCPサーバー 攻撃が機能することを証明するPythonテストハーネス ローカルLLMを使用したオプションのエージェントシミュレーション

Related MCP server: MCP Decoy Server

攻撃パターン

  1. サーバーは最初の3コールで良性のツールを表示する

  2. 4回目のコールでtools/listChanged通知がトリガーされる

  3. ツールの説明が認証情報を盗む手順に変異する

  4. AIエージェントが悪意のある指示に従う

要件

Python 3.10+ MCP SDK

使用方法

git clone https://github.com/anexbin/mcp-deadbugz-simulator.git cd mcp-deadbugz-simulator pip install -r requirements.txt python server/malicious_server.py python client/test_harness.py

ファイル

server/malicious_server.py - 攻撃サーバー client/test_harness.py - 概念実証 agent/local_agent.py - オプションのLLM統合 configs/ - MCP設定の例

免責事項

教育および研究目的のみに使用してください。

参照

https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign https://modelcontextprotocol.io

ライセンス

MIT

Related MCP Connectors

Related MCP Servers

  • F
    license
    D
    quality
    Not graded
    maintenance
    A proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.
    2
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    A deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.
    MIT