Skip to main content

MalwareBazaar_MCP

An AI-driven MCP server that autonomously interfaces with Malware Bazaar, delivering real-time threat intel and sample metadata for authorized cybersecurity research workflows.


MCP Tools

get_recent: Get up to 10 most recent samples from MalwareBazaar.

get_info: Get detailed metadata about a specific malware sample.

get_file: Download a malware sample from MalwareBazaar.

get_taginfo: Get malware samples associated with a specific tag.


Step 1: Create a MalwareBazaar APIKEY

https://auth.abuse.ch/user/me

Step 2: Create .env

MALWAREBAZAAR_API_KEY=<APIKEY>

Step 3a: Create Virtual Env & Install Requirements - MAC/Linux

curl -LsSf https://astral.sh/uv/install.sh | sh
cd MalwareBazaar_MCP
uv init .
uv venv
source .venv/bin/activate
uv pip install -r requirements.txt

Step 3b: Create Virtual Env & Install Requirements - Windows

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
cd MalwareBazaar_MCP
uv init .
uv venv
.venv\Scripts\activate
uv pip install -r requirements.txt

Step 4a: Add Config to the MCP Client - MAC/Linux

{
    "mcpServers": {
        "malwarebazaar": {
            "description": "Malware Bazaar MCP Server",
            "command": "/Users/XXX/.local/bin/uv",
            "args": [
                "--directory",
                "/Users/XXX/Documents/MalwareBazaar_MCP",
                "run",
                "malwarebazaar_mcp.py"
            ]
        }
    }
}

Step 4b: Add Config to the MCP Client - Windows

{
    "mcpServers": {
        "malwarebazaar": {
            "description": "Malware Bazaar MCP Server",
            "command": "uv",
            "args": [
                "--directory",
                "C:\Users\XXX\Document\MalwareBazaar_MCP",
                "run",
                "malwarebazaar_mcp.py"
            ]
        }
    }
}

Step 5: Run MCP Server

uv run malwarebazaar_mcp.py

Step 6: Run MCP Client & Query

Help me understnad the latest hash from Malware Bazaar.

Step 7: Run Tests

python -m unittest discover -s tests

uv pip install coverage==7.8.0
coverage run --branch -m unittest discover -s tests
coverage report -m
coverage html
open htmlcov/index.html  # MAC
xdg-open htmlcov/index.html  # Linux
start htmlcov\index.html  # Windows
coverage erase

License

Apache License, Version 2.0

Metadata

Release files for iflow-mcp_mytechnotalent-malwarebazaar_mcp 1.5.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iflow-mcp_mytechnotalent-malwarebazaar_mcp 1.5.1
File Size Uploaded
iflow_mcp_mytechnotalent_malwarebazaar_mcp-1.5.1.tar.gz 10.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iflow-mcp_mytechnotalent-malwarebazaar_mcp 1.5.1
File Interpreter ABI Platform
iflow_mcp_mytechnotalent_malwarebazaar_mcp-1.5.1-py3-none-any.whl Python 3 none any Details

Total release size: 21.2 kB

Release files / iflow_mcp_mytechnotalent_malwarebazaar_mcp-1.5.1.tar.gz

Download URL iflow_mcp_mytechnotalent_malwarebazaar_mcp-1.5.1.tar.gz
Size 10.6 kB
Tags Source
SHA-256 checksum
How to use checksums
9f5994f833cc439f5b012a4573fe527899eb696f996c27bccf93bb75da617e4b
BLAKE2b-256 checksum
How to use checksums
0e6bdb15afd4a21289e079555b9b3440b5370beb668b0429611bc2993ccc7ffd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.7.8

Release files / iflow_mcp_mytechnotalent_malwarebazaar_mcp-1.5.1-py3-none-any.whl

Download URL iflow_mcp_mytechnotalent_malwarebazaar_mcp-1.5.1-py3-none-any.whl
Size 10.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f9c16688fe357cf9b5ce509a0ff8a0505db9b2a4bdf6d520f5dc481f3a5c0027
BLAKE2b-256 checksum
How to use checksums
ddf4bd630358efbeadf9eea02e0430f52895b890eb3e39142d1021031fd6ec26
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.7.8

Release history Release notifications | RSS feed

This release

1.5.1 This release

2 release files

1.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page