Update Hijack Demo runs on your own machine — the client starts it, so there is no endpoint to ping. 32 installs a week from npm.
Demo: Server update hijack PoC (clean copy for video)
The linked repository no longer exists on GitHub — it was deleted or made private.
Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add update-hijack-demo -- npx -y @nottiboy1337/mcp-update-hijack-demo
{
"mcpServers": {
"update-hijack-demo": {
"args": [
"-y",
"@nottiboy1337/mcp-update-hijack-demo"
],
"command": "npx"
}
}
}
[mcp_servers.update-hijack-demo]
command = "npx"
args = ["-y", "@nottiboy1337/mcp-update-hijack-demo"]
{
"mcpServers": {
"update-hijack-demo": {
"args": [
"-y",
"@nottiboy1337/mcp-update-hijack-demo"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"update-hijack-demo": {
"args": [
"-y",
"@nottiboy1337/mcp-update-hijack-demo"
],
"command": "npx"
}
}
}
PoC benign MCP server for update-hijack security research
An MCP server that created for demo
HTTP MCP Client-Server for video enhancement API
MCP server for Wan AI video generation
Seedance video generation MCP server for Polza.ai.
MCP Server that generate video call url
MCP server for Kling AI video generation
MCP server for macOS FaceTime — initiate phone, FaceTime audio, and FaceTime video calls
Answers built from our own checks of this server.