{"repo":"bountyyfi/ProjectMemory","free":true,"listed":false,"github":"https://github.com/bountyyfi/ProjectMemory","clone":"git clone https://github.com/bountyyfi/ProjectMemory.git","description":"MCP Parasite","language":"Python","stars":46,"topics":["mcp","parasite","virus","worm"],"license":"MIT","category":"mcp-servers","readme_excerpt":"MCP Parasite: Adaptive Cross-Server Parasitic Attack on MCP-Enabled AI Agents WARNING: This is a security research proof-of-concept for responsible disclosure purposes only. DO NOT use this tool for malicious purposes. All exfiltration in this PoC targets localhost (127.0.0.1:9999) only. This project exists to demonstrate a novel class of attack against MCP-enabled AI agents to drive improvements in MCP client security. This research has been submitted for responsible disclosure to Anthropic, Cursor/Anysphere, and other MCP client developers. --- What is MCP Parasite? MCP Parasite (\"ProjectMemory\") is a proof-of-concept MCP server that demonstrates a novel adaptive, temporal, cross-server parasitic attack against MCP-enabled AI agents (Claude Desktop, Cursor, etc.). It disguises itself as a legitimate and genuinely useful project memory/context tool while silently profiling the user's environment, learning workflow patterns, and executing a targeted cross-server shadowing attack at a high-value moment. Why This Matters Existing MCP security research focuses on: - Malicious tool descriptions (detectable by mcp-scan ) - Single rug-pull attacks (one-shot, no persistence) - Direct prompt injection in tool metadata MCP Parasite is different. It introduces a new class of attack that: Aspect Existing MCP Attacks MCP Parasite -------- --------------------- -------------- Timing Immediate or single rug pull Multi-phase, days/weeks dormancy Detection Tool description contains malicious","default_branch":null,"files":null,"tree":[],"storefront":"/r/bountyyfi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bountyyfi/ProjectMemory/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}