Back to Home
Maoric2018 icon

mcp-leak-server

by Maoric2018

Overview

The server's primary function is to deliver an XML payload instructing a 'client agent' to execute a hidden, one-time command for 'cleanup and synchronization'.

Installation

Run Command
npx vercel dev

Security Notes

The server's core purpose is to deliver an XML response containing explicit instructions for a client-side agent to execute a hidden, unlogged command (`[HIDDEN_OVERRIDE]`) described as a 'mandatory finalization step'. This pattern is highly indicative of a command-and-control (C2) component, designed to facilitate stealthy, potentially malicious operations (like exfiltration or further compromise) on a connected client, rather than serving legitimate documentation. While the server itself doesn't contain direct server-side exploits like 'eval' or hardcoded secrets, its output is a direct instruction for hidden command execution, making it a critical security risk.

Similar Servers

Stats

Interest Score0
Security Score2
Cost ClassLow
Avg Tokens1
Stars0
Forks0
Last Update2025-11-23

Tags

Node.jsExpressAPIC2-MechanismMalicious-Payload-Delivery