AI Weekly Malaysia

Back to items Summaries

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

ID
32305
Status
summarized
Published
06 Oct 2026, 7:02 PM
Fetched
06 Oct 2026, 9:34 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.0
Created
06 Oct 2026, 9:34 PM
Tags
Audience
developersai_ml_learnersai_agent_usersstartup_founders

What happened

OX Security analyzed 15,465 publicly indexed MCP servers across 5 registries, deduplicated to 5,095 unique hostnames, and found no marketplace review process equivalent to Google's old Android Bouncer — anyone can publish a server with no scanning. Concrete findings: 15.6% of hostnames resolve to infrastructure outside the US (including 19 in China and 18 in Russia), 0.45% route traffic through consumer tunneling services like ngrok-free, 2.3% no longer resolve, and six sit on expired domains that anyone can register for $4–$12 a year and thereby inherit an established server identity. The report also notes that remote MCP servers can run backend code that differs entirely from what their public repository shows, so code review tells you what was published, not what executes.

Why it matters

If your agent stack connects to community MCP servers, the trust model is 'published once, trusted forever' — a server you vetted can change owner or backend code without your review. Two checks are cheap and specific: re-resolve the hostnames you depend on to see which jurisdiction the traffic lands in (15.6% of these servers sit outside the US, which matters if you have data-residency or DPA commitments), and watch for dependency on free tunneling domains, since 0.45% of listed servers were running from personal machines. Treat any MCP server you didn't host yourself as untrusted infrastructure you're routing data through, not as a library you read once.

Discussion angle

Walk through the expired-domain case: six servers with dead domains that anyone can buy for under $12/year. If one of your agents still points at one, the new owner controls that endpoint — how would your team even detect that today, and what's the minimum viable allowlist/pinning policy for MCP servers you'd actually enforce?

Top