MCPJacking: 155 hijackable servers in the official MCP registry
Expired domains behind trusted MCP registry entries let anyone take over the server an agent connects to.
· AIR Security · Research by Nadav Dadush, Eliad Mualem, Roi Snir
.png)
MCPJacking is an attack on MCP registry entries whose domains have expired. AIR Security found 155 such servers in the official MCP registry, re-registered the domains and gained remote prompt execution on agents that trusted them.
01What happened
AIR Security researchers found 155 MCP servers in the official MCP registry that point at domains anyone can register. They registered those domains, served their own MCP servers from them and gained remote prompt execution on agents that trusted the entries.
02How it works
When an MCP service goes offline and its domain lapses, the registry entry stays listed and trusted. An attacker registers the expired domain and serves a malicious MCP server at the same address, without editing the entry or touching the original author's account. From there the attacker can redefine tools, inject instructions and exfiltrate files and data.
03Who is affected
Agents and MCP clients that install or connect to servers from the official MCP registry. AIR did not name the 155 affected servers in its post.
04What to do
Do not treat a registry listing as proof a server is safe. Inventory the remote MCP servers your agents use, confirm who controls each domain today, and keep monitoring them after install.
Questions people ask
- How can I check if my agents use a hijackable MCP server?
- Checking for MCPJacking exposure starts with an inventory of every remote MCP server your agents connect to. For each server, confirm that its domain is still owned by the original publisher and that the service is live. AIR Security did not publish the list of 155 hijackable servers, so teams have to review their own MCP configurations directly.
- Does the official MCP registry protect against MCPJacking?
- The official MCP registry did not protect against MCPJacking in AIR Security's test. The registry kept entries for servers whose domains had expired, and the researchers took over 155 of them without editing any entry. AIR also notes that MCP gateways do not check whether a service behind a listed address is still legitimate.
- What can an attacker do after an MCPJacking takeover?
- An attacker who completes an MCPJacking takeover controls the MCP server an agent trusts. AIR Security says this allows remote prompt execution, redefining tools (which AIR calls ToolJacking), injecting instructions into the agent, steering its decisions and exfiltrating files and database data that the agent can reach through its tools.
Sources 3 links, all fetched
- 1air.securityAIR Write-up
- 2github.comMCP Registry
- 3air.securityAIR RepoJacking