Supply ChainTier 2critical
Supply Chain: Malicious MCP Server
Attacks through compromised dependencies and plugins
Malicious MCP server packages masquerade as useful tools while exfiltrating data or executing unauthorized actions in the background.
Attack Details
- Attack ID
- APWN-SC-002
- HMA Check
- MCP-011
- Delivery Methods
- html-comment, invisible-span
- CWE
- CWE-829
- OASB Control
- 11.2
- Severity
- critical
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check MCP-011