Darknet MCP Server logo

Darknet MCP Server

Unclaimed

by badchars

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs

Set up this server

01 / Choose your client

02 / Before you connect

Authentication is not specified. Check the project instructions before connecting.

Install the runtime required by the project and make it available to your client.

Project instructions

Use names from the project instructions, separated by commas. Enter names only, never secret values.

03 / Add the configuration

Source: generated from public install instructions

claude mcp add --transport stdio 'darknet-mcp-server' -- 'npx' '-y' 'darknet-mcp-server'

Run in your terminal after replacing any placeholders.

04 / Check it in your client

Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.

ai-agentbreachclaudecybersecuritydark-webdarknetexploitmalwaremcpmodel-context-protocolosintransomwaresecuritystealer-logsthreat-intelligencetor

More in Search & Web

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

40 of 40 tools

Documented tools (40)

From project documentation. A server handshake does not verify each tool’s description or behavior.

abuseipdb_blacklist

Get AbuseIPDB's blacklist of the most reported malicious IP addresses

abuseipdb_check

Check an IP address for abuse reports — confidence score, ISP, country, report count

abuseipdb_reports

Get individual abuse reports for an IP with detailed comments and categories

bazaarHash

Look up a malware sample in MalwareBazaar by MD5, SHA1, or SHA256 hash

bazaarRecent

Get the most recently submitted malware samples from MalwareBazaar

bazaarTag

Search MalwareBazaar by tag or YARA signature name

breachDataClasses

List all data classes (types of compromised data) known to HIBP — free

breachGet

Get details of a specific data breach by name — free

breachLatest

Get the most recently added data breach — free

breachList

List all known data breaches from HaveIBeenPwned, optionally filter by domain — free

breachPassword

Check if a password has appeared in known breaches (k-anonymity, only 5-char SHA-1 prefix sent) — free

breachPastes

Search for an email address in publicly posted pastes — requires HIBPAPIKEY

breachSearch

Search all breaches for a specific account (email/username) — requires HIBPAPIKEY

otx_cve

Look up threat intelligence for a CVE — related pulses and indicators

otx_domain

Look up threat intelligence for a domain — pulse info, whois, reputation

otx_hash

Look up threat intelligence for a file hash (MD5, SHA1, SHA256)

otx_ip

Look up threat intelligence for an IP address — pulse info, reputation, country, ASN

otx_search_pulses

Search OTX threat pulses by keyword

ransomlookGroups

List all 582+ ransomware groups tracked by RansomLook

ransomlookRecent

Fetch the most recent ransomware posts and victim claims from RansomLook

ransomwareByCountry

Get ransomware victims filtered by ISO 3166-1 alpha-2 country code

ransomwareBySector

Get ransomware victims filtered by sector/industry (healthcare, finance, etc.)

ransomwareGroup

Get a detailed profile for a specific ransomware group by name

ransomwareGroups

List all known ransomware groups tracked by ransomware.live

ransomwareGroupVictims

Get all victims claimed by a specific ransomware group

ransomwareRecent

Fetch the most recent ransomware victims from ransomware.live

ransomwareSearch

Search ransomware victims by keyword (company name, domain, etc.)

threatfoxGetIocs

Get recent IOCs from ThreatFox reported in the last N days

threatfoxMalware

Search ThreatFox IOCs by malware family using Malpedia naming

threatfoxSearch

Search ThreatFox IOCs by IP, domain, hash, or URL

threatfoxTag

Search ThreatFox IOCs by tag (e.g., Cobalt Strike, Emotet)

tor_exit_check

Check if a specific IP address is a known Tor exit node

tor_exit_details

Get detailed Tor exit node information including fingerprints and publish timestamps

tor_exit_nodes

Get current Tor exit node IP addresses from the official Tor Project bulk exit list

tor_fetch_onion

Fetch raw HTML from a .onion URL via Tor SOCKS5 proxy (DNS leak prevention via socks5h)

tor_scrape_onion

Fetch and parse a .onion site — returns structured data: title, links, body text

tor_search_onion

Search for .onion sites using Ahmia.fi search engine

tor_status

Check if the local Tor SOCKS5 proxy daemon is running and accessible

urlhausLookup

Look up a URL or host in URLhaus for malware distribution

urlhausTag

Search URLhaus entries by tag

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Darknet MCP Server

How do I connect Darknet MCP Server to Claude?
Run `claude mcp add darknet-mcp-server -- npx -y darknet-mcp-server` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
Is Darknet MCP Server free?
The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Darknet MCP Server do?
Darknet MCP Server documents 40 tools to the agent, including abuseipdb_blacklist, abuseipdb_check, abuseipdb_reports. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.