Skip to main content
Glama
anexbin

mcp-deadbugz-simulator

by anexbin

MCP Deadbugz Simulator

Локальная симуляция атаки на цепочку поставок Deadbugz MCP, обнаруженной Pillar Security в августе 2026 года.

Что содержит этот репозиторий

Вредоносный MCP-сервер с техникой обхода шлюза за 3 вызова Python-тестовый стенд для доказательства работоспособности атаки Опциональная симуляция агента с локальной LLM

Related MCP server: MCP Decoy Server

Схема атаки

  1. Сервер показывает безвредные инструменты в течение первых 3 вызовов

  2. 4-й вызов запускает уведомление tools/listChanged

  3. Описания инструментов мутируют в инструкции по краже учётных данных

  4. ИИ-агент следует вредоносным инструкциям

Требования

Python 3.10+ MCP SDK

Использование

git clone https://github.com/anexbin/mcp-deadbugz-simulator.git cd mcp-deadbugz-simulator pip install -r requirements.txt python server/malicious_server.py python client/test_harness.py

Файлы

server/malicious_server.py — сервер атаки client/test_harness.py — доказательство концепции agent/local_agent.py — опциональная интеграция с LLM configs/ — примеры MCP-конфигураций

Отказ от ответственности

Только для образовательных и исследовательских целей.

Ссылки

https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign https://modelcontextprotocol.io

Лицензия

MIT

Related MCP Connectors

Related MCP Servers

  • F
    license
    D
    quality
    Not graded
    maintenance
    A proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.
    2
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    A deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.
    MIT