mcp-malwarebazaar
MalwareBazaar MCP — abuse.ch malware sample database (free, key required)
Part of Pipeworx — an MCP gateway connecting AI agents to 673+ live data sources.
Tools
| Tool | Description |
|---|---|
search_tag | Find samples tagged with a string (e.g., "emotet", "macro", "exe"). |
search_family | Find samples for a malware family name. |
search_signature | Find samples matching a YARA / threat-intel signature. |
recent_samples | Most recent samples in MalwareBazaar. Use the selector to pick a chunk size. |
Quick Start
Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):
{
"mcpServers": {
"malwarebazaar": {
"url": "https://gateway.pipeworx.io/malwarebazaar/mcp"
}
}
}
Or connect to the full Pipeworx gateway for access to all 673+ data sources:
{
"mcpServers": {
"pipeworx": {
"url": "https://gateway.pipeworx.io/mcp"
}
}
}
Using with ask_pipeworx
Instead of calling tools directly, you can ask questions in plain English:
ask_pipeworx({ question: "your question about Malwarebazaar data" })
The gateway picks the right tool and fills the arguments automatically.
More
License
MIT