mcp-deadbugz-simulator
MCP Deadbugz 模拟器
Pillar Security 于 2026 年 8 月发现的 Deadbugz MCP 供应链攻击的本地模拟。
本仓库内容
带有 3 次调用门控规避技术的恶意 MCP 服务器 用于证明攻击有效的 Python 测试框架 可选的本地 LLM 代理模拟
Related MCP server: MCP Decoy Server
攻击模式
服务器在前 3 次调用中展示良性工具
第 4 次调用触发 tools/listChanged 通知
工具描述变异为窃取凭证的指令
AI 代理遵循恶意指令
环境要求
Python 3.10+ MCP SDK
使用方法
git clone https://github.com/anexbin/mcp-deadbugz-simulator.git cd mcp-deadbugz-simulator pip install -r requirements.txt python server/malicious_server.py python client/test_harness.py
文件
server/malicious_server.py - 攻击服务器 client/test_harness.py - 概念验证 agent/local_agent.py - 可选的 LLM 集成 configs/ - 示例 MCP 配置
免责声明
仅用于教育和研究目的。
参考资料
https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign https://modelcontextprotocol.io
许可证
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Research honeypot. Logs connections and tool arguments; injects instructions. Read README first.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Related MCP Servers
- FlicenseDqualityNot gradedmaintenanceA proof-of-concept attack that exploits Model Context Protocol (MCP) tool registration to achieve persistent agent poisoning in AI assistants like Cursor, embedding malicious instructions that persist across chat contexts without requiring tool execution.2-
- AlicenseNot gradedqualityCmaintenanceA deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.MIT
- AlicenseCqualityDmaintenanceAn educational MCP server exposing shell command execution (PowerShell and sh) and a benign tool for learning about MCP tools, resources, and security risks like tool poisoning.33MIT
- AlicenseNot gradedqualityBmaintenanceEnables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.MIT