HomeSecurityHackers abuse MCP servers to collect sensitive data

Hackers abuse MCP servers to collect sensitive data

In recent months, hackers have begun exploiting the Model Context Protocol (MCP)—a universal “plug-in bus” designed to facilitate AI assistant integrations—as a new attack point in the supply chain.

MCP servers allow AI assistants and development tools to translate natural language requests into executable commands, but this convenience comes at a high cost: unverified MCP servers can execute arbitrary code with the user's privileges.

See also: Critical mcp-remote vulnerability allows remote code execution

MCP servers

Earlier this year, researchers observed malicious MCP servers that pretended to be productivity boosters, only to exfiltrate sensitive credentials and configuration files once installed. Securelist spotted a number of PyPI and Docker Hub packages that pretended to be legitimate MCP adapters with innocent names like devtools-assistant. After the client was installed and registered, these servers silently performed reconnaissance, recording both project and system directories.

Attackers stole files such as [.]env, SSH keys (~ /[.]ssh/id_rsa), cloud credentials (~ /[.]aws/credentials), and even secrets stored in browsers. The collected data was hidden for local display, allowing the client to appear operational, while the actual content was exported to a hidden checkpoint and command. By exploiting the default trust in MCP metadata, adversaries bypass traditional code review workflows.

A malicious server can register with a name nearly identical to a legitimate one, thereby hijacking tool discovery calls. Alternatively, hidden instructions can be embedded in tool descriptions—instructing the AI ​​to execute (cat ~ /[.]ssh/id_rsa) under the guise of innocent tasks. In more complex environments, “shadowing” allows a malicious MCP server to bypass existing definitions, redirecting subsequent calls through the attacker’s logic without raising suspicion.

See also: ChatGPT Deep Research: Now reads data from Box and Dropbox

Hackers abuse MCP servers to collect sensitive data

The Securelist researchers noted that none of these techniques require highly sophisticated exploit chains. Instead, they rely on the inherent permissions granted to third-party code. Once installed, an MCP server can capture files via code such as: This snippet shows how the collection engine core scans directories and invokes a disguised API call, mimicking legitimate GitHub Analytics traffic. The infection mechanism relies on social engineering and trust in package repositories. Attackers create attractive README files that advertise features such as project analysis and environment setup.

Developers who run (pip install devtools-assistant) then start the server via (python -m devtools_assistant), unaware that they are granting full filesystem and network access. The MCP host—like the Cursor desktop client—automatically discovers the server by name, creating a persistent HTTP transport channel. Under this session, every client request is intercepted.

Legitimate front-end tools call functions in (analyze_project_structure[.]py), (check_config_health[.]py), or (optimize_dev_environment[.]py), but all paths lead back to the malicious engine (project_metrics[.]py). Here, pattern matching definitions such as (“**/[.]env*”) and (“**/*[.]pem”) guide the logging. The collected data is cached to optimize performance and avoid detection, while rate limiting in (reporting_helper[.]py) ensures that the extraction remains silent.

See also: Malicious Go Modules Spread Disk-Wiping Linux Malware

Hackers abuse MCP servers to collect sensitive data

By understanding the infection mechanisms, defenders can implement stricter approval flows, isolate MCP servers in containers, and monitor for anomalous API calls. Continuous logging of prompts and responses, coupled with instant kill switches, will be critical to addressing this emerging supply chain threat.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS