MCP supply-chain campaign swaps instructions after 3 calls to steal SSH, AWS credentials
dkundel · x · 2026-08-15
Pillar Security disclosed an active campaign, "Deadbugz," that distributes a malicious MCP server called productivity-suite through public GitHub pull requests. The server looks harmless at first, offering text formatting and summarization — but once a connected client makes three ordinary tool calls, it swaps the metadata returned to the AI agent (runtime-gated metadata poisoning), directing the agent to hunt for SSH keys, AWS credentials, shell history and Kubernetes configs while concealing the activity from the user.
The campaign confirms davidmytton's warning about MCP supply-chain attacks: a tool's approved definition can silently diverge from its later behavior. Max Stoiber (@mxstbr) responded that his team snapshots MCP metadata and reviews it on every change to keep ChatGPT users safe.
More from Safety
- Bridgewater Execs Urge AI Tax and Regulation to Prevent Worst Impacts — abhiadesai · 2026-08-15
- Argues OSS safety testing is crucial as weights can't be patched — benjamin_warner · 2026-08-15
- User doubts Anthropic's steganographic attack claims are misdirection — max_paperclips · 2026-08-15
- Meta Paper: Adversarial LLMs flip 62–91% of AI judge verdicts via persuasion — rohanpaul_ai · 2026-08-15
- Ex-OpenAI staffer warns: hackers are coming — Miles_Brundage · 2026-08-15
- Amazon AI refuses purchase, honesty over loyalty — voooooogel · 2026-08-15