# Virustotal (MCP server)

> Virustotal is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for querying VirusTotal API with comprehensive security analysis tools. It has 150 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-virustotal.

A Model Context Protocol (MCP) server for querying the VirusTotal API. This server provides comprehensive security analysis tools with automatic relationship data fetching. It integrates seamlessly with MCP-compatible applications like Claude Desktop.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/w0h1v/mcp-virustotal |
| GitHub stars | 150 |
| License | MIT |
| Language | TypeScript |
| Transport | stdio |
| Packages | npm: @burtthecoder/mcp-virustotal |
| Remote URL | none |
| Needs API key | yes |
| Official | no |
| Works with | Claude Desktop, Claude Code, Cursor, VS Code |
| Category | Other |
| Latest release | none |
| Last commit | Sep 8, 2026 |
| MCP registry name | io.github.BurtTheCoder/virustotal |

## Install

### Claude Desktop (claude_desktop_config.json)

```json
{
  "mcpServers": {
    "virustotal": {
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "your-value"
      }
    }
  }
}
```

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

### Claude Code

```sh
claude mcp add --env VIRUSTOTAL_API_KEY=your-value --transport stdio virustotal -- npx -y @burtthecoder/mcp-virustotal
```

### Cursor (.cursor/mcp.json)

```json
{
  "mcpServers": {
    "virustotal": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "your-value"
      }
    }
  }
}
```

Project file; use ~/.cursor/mcp.json to enable it in every project.

### VS Code (.vscode/mcp.json)

```json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "virustotal_api_key",
      "description": "VIRUSTOTAL_API_KEY",
      "password": true
    }
  ],
  "servers": {
    "virustotal": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-virustotal"
      ],
      "env": {
        "VIRUSTOTAL_API_KEY": "${input:virustotal_api_key}"
      }
    }
  }
}
```

Config formats checked against the official docs on 2026-10-07.

## Environment variables

- `VIRUSTOTAL_API_KEY` (secret) (required): Your VirusTotal API key

## Tools

- `hash`: MD5, SHA-1 or SHA-256 hash of the file
- `domain`: Domain name to analyze
- `relationships`: Array of specific relationships to include in the report
- `relationship`: Type of relationship to query
- `limit`: Maximum number of related objects to retrieve (1-40)
- `cursor`: Continuation cursor for pagination
- `query`: Search query. Examples: a SHA-256 hash, evil.com, 8.8.8.8, type:peexe size:90kb+ tag:signed positives:5+

## Similar MCP servers

- [Reactive Resume](https://appsgit.com/mcp-servers/reactive-resume): A one-of-a-kind resume builder that keeps your privacy in mind. (43,921 stars, MIT)
- [N8n MCP](https://appsgit.com/mcp-servers/n8n-mcp): A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you. (23,047 stars, MIT)
- [XHS Downloader](https://appsgit.com/mcp-servers/xhs-downloader): 小红书（XiaoHongShu、RedNote）链接提取/作品采集工具. (12,922 stars, GPL-3.0)
- [MCP Use](https://appsgit.com/mcp-servers/mcp-use): The fullstack MCP framework to develop MCP Apps for ChatGPT / Claude & MCP Servers for AI Agents. (10,726 stars, MIT)
- [Ha MCP](https://appsgit.com/mcp-servers/ha-mcp): Comprehensive Model Context Protocol server for managing Home Assistant through AI assistants. (4,964 stars, MIT)
- [MCP Server Chart](https://appsgit.com/mcp-servers/mcp-server-chart): A Model Context Protocol server for generating charts using AntV. (4,391 stars, MIT, needs API key)

---

Canonical page: https://appsgit.com/mcp-servers/virustotal
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
