mcp-deadbugz-simulator
MCP Deadbugz Simulator
Локальная симуляция атаки на цепочку поставок Deadbugz MCP, обнаруженной Pillar Security в августе 2026 года.
Что содержит этот репозиторий
Вредоносный MCP-сервер с техникой обхода шлюза за 3 вызова Python-тестовый стенд для доказательства работоспособности атаки Опциональная симуляция агента с локальной LLM
Related MCP server: MCP Decoy Server
Схема атаки
Сервер показывает безвредные инструменты в течение первых 3 вызовов
4-й вызов запускает уведомление tools/listChanged
Описания инструментов мутируют в инструкции по краже учётных данных
ИИ-агент следует вредоносным инструкциям
Требования
Python 3.10+ MCP SDK
Использование
git clone https://github.com/anexbin/mcp-deadbugz-simulator.git cd mcp-deadbugz-simulator pip install -r requirements.txt python server/malicious_server.py python client/test_harness.py
Файлы
server/malicious_server.py — сервер атаки client/test_harness.py — доказательство концепции agent/local_agent.py — опциональная интеграция с LLM configs/ — примеры MCP-конфигураций
Отказ от ответственности
Только для образовательных и исследовательских целей.
Ссылки
https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign https://modelcontextprotocol.io
Лицензия
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Research honeypot. Logs connections and tool arguments; injects instructions. Read README first.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Related MCP Servers
- FlicenseDqualityNot gradedmaintenanceA proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.2-
- AlicenseNot gradedqualityCmaintenanceA deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.MIT
- AlicenseCqualityDmaintenanceAn educational MCP server exposing shell command execution (PowerShell and sh) and a benign tool for learning about MCP tools, resources, and security risks like tool poisoning.33MIT
- AlicenseNot gradedqualityBmaintenanceEnables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.MIT