Skip to content
appsgit

Virustotal

Virustotal is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for querying VirusTotal API with comprehensive security analysis tools. It has 150 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-virustotal.

github.com/w0h1v/mcp-virustotal (opens in a new tab)

  • Needs API key
  • Other
  • MIT
  • Actively maintained

Install Virustotal

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "virustotal": {
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "your-value"
      }
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --env VIRUSTOTAL_API_KEY=your-value --transport stdio virustotal -- npx -y @burtthecoder/mcp-virustotal

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "virustotal": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "your-value"
      }
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "virustotal_api_key",
      "description": "VIRUSTOTAL_API_KEY",
      "password": true
    }
  ],
  "servers": {
    "virustotal": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "${input:virustotal_api_key}"
      }
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Environment variables

Variables the server reads at startup.

NameRequiredDescription
VIRUSTOTAL_API_KEYsecretYesYour VirusTotal API key

Tools (7)

Parsed from the Tools section of the README; check the repository for the current list.

  • hash

    MD5, SHA-1 or SHA-256 hash of the file

  • domain

    Domain name to analyze

  • relationships

    Array of specific relationships to include in the report

  • relationship

    Type of relationship to query

  • limit

    Maximum number of related objects to retrieve (1-40)

  • cursor

    Continuation cursor for pagination

  • query

    Search query. Examples: a SHA-256 hash, evil.com, 8.8.8.8, type:peexe size:90kb+ tag:signed positives:5+

About Virustotal

A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.

  • malware-analysis
  • mcp
  • security
  • threat-intelligence
  • typescript
  • virustotal
  • ai-tools
  • claude
  • cybersecurity
  • ioc

FAQ

Virustotal FAQ

Still curious? Email info@appsgit.com.

What is Virustotal?

Virustotal is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for querying VirusTotal API with comprehensive security analysis tools. It has 150 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-virustotal. The source code is at github.com/w0h1v/mcp-virustotal.

How do I install the Virustotal MCP server?

Add the command npx -y @burtthecoder/mcp-virustotal to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is Virustotal free?

The server is open source under the MIT license, so running it is free. It needs credentials (VIRUSTOTAL_API_KEY) for the service it connects to, which may require a paid account.

Is Virustotal actively maintained?

The most recent commit was on Sep 8, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.