Virustotal
Virustotal is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for querying VirusTotal API with comprehensive security analysis tools. It has 150 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-virustotal.
- Needs API key
- Other
- MIT
- Actively maintained
Install Virustotal
Generated from the server's MCP registry entry. Replace your-value with your own values.
Claude Desktop
{
"mcpServers": {
"virustotal": {
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-virustotal"
],
"env": {
"VIRUSTOTAL_API_KEY": "your-value"
}
}
}
}Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.
Claude Code
claude mcp add --env VIRUSTOTAL_API_KEY=your-value --transport stdio virustotal -- npx -y @burtthecoder/mcp-virustotalCursor
{
"mcpServers": {
"virustotal": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-virustotal"
],
"env": {
"VIRUSTOTAL_API_KEY": "your-value"
}
}
}
}Project file; use ~/.cursor/mcp.json to enable it in every project.
VS Code
{
"inputs": [
{
"type": "promptString",
"id": "virustotal_api_key",
"description": "VIRUSTOTAL_API_KEY",
"password": true
}
],
"servers": {
"virustotal": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-virustotal"
],
"env": {
"VIRUSTOTAL_API_KEY": "${input:virustotal_api_key}"
}
}
}
}Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).
Environment variables
Variables the server reads at startup.
| Name | Required | Description |
|---|---|---|
VIRUSTOTAL_API_KEYsecret | Yes | Your VirusTotal API key |
Tools (7)
Parsed from the Tools section of the README; check the repository for the current list.
hashMD5, SHA-1 or SHA-256 hash of the file
domainDomain name to analyze
relationshipsArray of specific relationships to include in the report
relationshipType of relationship to query
limitMaximum number of related objects to retrieve (1-40)
cursorContinuation cursor for pagination
querySearch query. Examples: a SHA-256 hash, evil.com, 8.8.8.8, type:peexe size:90kb+ tag:signed positives:5+
About Virustotal
A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.
- malware-analysis
- mcp
- security
- threat-intelligence
- typescript
- virustotal
- ai-tools
- claude
- cybersecurity
- ioc
Similar MCP servers
More other MCP servers
Reactive Resume
reactive-resume/reactive-resume
A one-of-a-kind resume builder that keeps your privacy in mind.
OtherTypeScriptN8n MCP
czlonkowski/n8n-mcp
A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you.
OtherTypeScriptXHS Downloader
JoeanAmier/XHS-Downloader
小红书(XiaoHongShu、RedNote)链接提取/作品采集工具.
OtherJavaScriptMCP Use
mcp-use/mcp-use
The fullstack MCP framework to develop MCP Apps for ChatGPT / Claude & MCP Servers for AI Agents.
OtherTypeScriptHa MCP
homeassistant-ai/ha-mcp
Comprehensive Model Context Protocol server for managing Home Assistant through AI assistants.
OtherPythonMCP Server Chart
antvis/mcp-server-chart
A Model Context Protocol server for generating charts using AntV.
OtherTypeScript
What is Virustotal?
Virustotal is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for querying VirusTotal API with comprehensive security analysis tools. It has 150 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-virustotal. The source code is at github.com/w0h1v/mcp-virustotal.
How do I install the Virustotal MCP server?
Add the command npx -y @burtthecoder/mcp-virustotal to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.
Is Virustotal free?
The server is open source under the MIT license, so running it is free. It needs credentials (VIRUSTOTAL_API_KEY) for the service it connects to, which may require a paid account.
Is Virustotal actively maintained?
The most recent commit was on Sep 8, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.