Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
- ID
- 32305
- Status
- summarized
- Published
- 06 Oct 2026, 7:02 PM
- Fetched
- 06 Oct 2026, 9:34 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.0
- Created
- 06 Oct 2026, 9:34 PM
- Tags
- Audience
- developersai_ml_learnersai_agent_usersstartup_founders
What happened
OX Security analyzed 15,465 publicly indexed MCP servers across 5 registries, deduplicated to 5,095 unique hostnames, and found no marketplace review process equivalent to Google's old Android Bouncer — anyone can publish a server with no scanning. Concrete findings: 15.6% of hostnames resolve to infrastructure outside the US (including 19 in China and 18 in Russia), 0.45% route traffic through consumer tunneling services like ngrok-free, 2.3% no longer resolve, and six sit on expired domains that anyone can register for $4–$12 a year and thereby inherit an established server identity. The report also notes that remote MCP servers can run backend code that differs entirely from what their public repository shows, so code review tells you what was published, not what executes.
Why it matters
If your agent stack connects to community MCP servers, the trust model is 'published once, trusted forever' — a server you vetted can change owner or backend code without your review. Two checks are cheap and specific: re-resolve the hostnames you depend on to see which jurisdiction the traffic lands in (15.6% of these servers sit outside the US, which matters if you have data-residency or DPA commitments), and watch for dependency on free tunneling domains, since 0.45% of listed servers were running from personal machines. Treat any MCP server you didn't host yourself as untrusted infrastructure you're routing data through, not as a library you read once.
Discussion angle
Walk through the expired-domain case: six servers with dead domains that anyone can buy for under $12/year. If one of your agents still points at one, the new owner controls that endpoint — how would your team even detect that today, and what's the minimum viable allowlist/pinning policy for MCP servers you'd actually enforce?