Two weeks ago, a Windows trojan slipped into my MCP (Model Context Protocol) marketplace. The malware was Trojan:Win64/Lazy.PGPK!MTB, hidden inside a nested zip in a skill package.

This is the technical writeup of what happened, what I built to prevent it, and the architecture of the 8-layer defense pipeline now running in production.

The attack

Vector: Typosquatting GitHub repository

A legitimate MCP server prospector-mcp-email-finder existed. An attacker created a typosquatting copy at JuanquiFortuny/prospector-mcp-email-finder (now taken down) with an identical README — but with a "Download Latest Release" badge linking to a malicious zip on raw.githubusercontent.com.