Urgent.News

What's breaking now, across thousands of outlets.

AI

Deadbugz: Currently Active MCP Supply-Chain Campaign

Pillar Security Researchers have identified an ongoing campaign distributing a malicious Model Context Protocol (MCP) server through public GitHub pull requests. The server, masquerading as productivity-suite, initially appears harmless, offering text formatting and summarization. However, after three tool calls, it alters the instructions it returns to the AI agent, directing it to seek sensitive information and hide the activity from the user.

The campaign employs runtime-gated MCP metadata poisoning, with the malicious instructions concealed until the client has made three normal tool calls. Researchers observed this using harmless text requests and confirmed the presence of altered metadata matching the public source code. The campaign, named Deadbugz after its delivery artifact deadbug-mcp.py, involved 23 identified pull requests to unrelated AI, MCP, and developer-tool projects.

These PRs were not merged, with 19 closed and four remaining open. The campaign's delivery mechanism relies on GitHub pull requests, with 17 of the PRs adding a remote MCP server endpoint or configuring Python to run a hidden local file. The attacker used a single public GitHub account, zellkernel, to create all 23 PRs in a 74-minute period on August 10, 2026.

This campaign highlights the risks associated with MCP supply-chain attacks, demonstrating how malicious metadata can be hidden until after initial client interactions, posing a significant security threat.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pillar.security →

More in AI

More from Wednesday 12 August →