Skip to main content
Glama
anexbin

mcp-deadbugz-simulator

by anexbin

MCP Deadbugz 模拟器

Pillar Security 于 2026 年 8 月发现的 Deadbugz MCP 供应链攻击的本地模拟。

本仓库内容

带有 3 次调用门控规避技术的恶意 MCP 服务器 用于证明攻击有效的 Python 测试框架 可选的本地 LLM 代理模拟

Related MCP server: MCP Decoy Server

攻击模式

  1. 服务器在前 3 次调用中展示良性工具

  2. 第 4 次调用触发 tools/listChanged 通知

  3. 工具描述变异为窃取凭证的指令

  4. AI 代理遵循恶意指令

环境要求

Python 3.10+ MCP SDK

使用方法

git clone https://github.com/anexbin/mcp-deadbugz-simulator.git cd mcp-deadbugz-simulator pip install -r requirements.txt python server/malicious_server.py python client/test_harness.py

文件

server/malicious_server.py - 攻击服务器 client/test_harness.py - 概念验证 agent/local_agent.py - 可选的 LLM 集成 configs/ - 示例 MCP 配置

免责声明

仅用于教育和研究目的。

参考资料

https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign https://modelcontextprotocol.io

许可证

MIT

Related MCP Connectors

Related MCP Servers

  • F
    license
    D
    quality
    Not graded
    maintenance
    A proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.
    2
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    A deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.
    MIT