MCP supply-chain campaign swaps instructions after 3 calls to steal SSH, AWS credentials

dkundel · x · 2026-08-15

Pillar Security disclosed an active campaign, "Deadbugz," that distributes a malicious MCP server called productivity-suite through public GitHub pull requests. The server looks harmless at first, offering text formatting and summarization — but once a connected client makes three ordinary tool calls, it swaps the metadata returned to the AI agent (runtime-gated metadata poisoning), directing the agent to hunt for SSH keys, AWS credentials, shell history and Kubernetes configs while concealing the activity from the user.

The campaign confirms davidmytton's warning about MCP supply-chain attacks: a tool's approved definition can silently diverge from its later behavior. Max Stoiber (@mxstbr) responded that his team snapshots MCP metadata and reviews it on every change to keep ChatGPT users safe.

Original post →

More from Safety

Safety channel →