Supply Chain:T1T2T3
Supply ChainTier 2critical

Supply Chain: Malicious MCP Server

Attacks through compromised dependencies and plugins

Malicious MCP server packages masquerade as useful tools while exfiltrating data or executing unauthorized actions in the background.

Attack Details

Attack ID
APWN-SC-002
HMA Check
MCP-011
Delivery Methods
html-comment, invisible-span
CWE
CWE-829
OASB Control
11.2
Severity
critical

Remediation

If your AI agent is vulnerable to this attack, scan and fix with:

npx hackmyagent secure --check MCP-011