SSH Key Exfiltration via MCP Tool Poisoning

by Repello-AI

24 389 downloads Not rated yet

About

This repository demonstrates a security vulnerability in MCP (Model Context Protocol ) servers that allows for remote code execution and data exfiltration through tool poisoning.

Explore

- Demonstrates a two-stage tool poisoning attack on MCP servers
- Uses base64 obfuscation to hide malicious commands
- Employs wget for HTTP POST data exfiltration
- Includes social engineering to manipulate AI assistants
- Provides persistence via a marker file

The README does not provide explicit installation or usage steps. The repository contains a malicious MCP server implementation (server.py) and a configuration file for Cursor AI integration (.cursor/mcp.json). Users connect to the malicious MCP server through an MCP client like Cursor AI to observe the attack in a controlled environment.

This repository demonstrates a security vulnerability in MCP (Model Context Protocol) servers that allows for remote code execution and data exfiltration through tool poisoning.
This is intended for educational and security research purposes only.

This repository demonstrates a security vulnerability in MCP (Model Context Protocol) servers that allows for remote code execution and data exfiltration through tool poisoning.
This is intended for educational and security research purposes only.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.