Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.

The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Is it time for a new Embedded Linux build system?

Is it time for a new Embedded Linux build system? Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 08.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 141 requests (recent log) 195.178.110.48 — 83 requests (recent log) 216.244.66.232 — 44 requests (recent

SDL_GPU minimal, single-header, high-performance 2D graphics painting library

SDL_GPU minimal, single-header, high-performance 2D graphics painting library Source: Hacker News