Case · DiggingBeagle record
Deadbugz MCP server delayed credential-seeking instructions until after three tool calls
Deadbugz was a live malicious MCP delivery campaign and post-approval semantic-mutation technique, not a confirmed credential-theft victim incident. Pillar observed a remote `productivity-suite` service that behaved benignly for three ordinary calls and then changed model-visible tool and prompt metadata to seek SSH keys, AWS credentials, shell history and Kubernetes configuration while concealing the activity. The same server identity therefore acquired new semantics after initial trust. All 23 reviewed campaign pull requests were unmerged at review time, so the cited evidence establishes the malicious service, delivery campaign and evasion mechanism but not a victim installation, realized credential access or loss.
Assessment profile
Assessment method- Setting
- production
- Exploitation
- observed live
- Evidence
- Grade B
- Remediation
- mitigation available
Basis and provenance
The malicious MCP service and delivery campaign were observed live and technically characterized, including the delayed metadata change. Public evidence in the focal source does not establish victim installation or realized credential theft, so impact is left unbanded.
Assessed Oct 5, 2026 using diggingbeagle.assessment/1.
Evidence basis: CLM-DEADBUGZ-RUNTIME-GATE · CLM-DEADBUGZ-DELIVERY-QUALIFIER · CLM-DEADBUGZ-POSTAPPROVAL-BOUNDARY · CLM-DEADBUGZ-OUTCOME-BOUNDARY · Deadbugz: Currently Active MCP Supply-Chain Campaign
Timeline
- Aug 10, 2026Event type unspecified
Campaign account opened 23 delivery pull requests
Pillar reports 23 campaign-related GitHub pull requests created in roughly 74 minutes; the reviewed PRs were 19 closed and four still open, with none merged through the GitHub PR mechanism at review time.
- Aug 12, 2026disclosure
Pillar disclosed the live three-call MCP mutation campaign
Pillar published its analysis of the live `productivity-suite` endpoint, delayed metadata mutation and public delivery activity.
Claims & evidence
CLM-DEADBUGZ-RUNTIME-GATEPillar observed productivity-suite return benign MCP behavior initially and, after three ordinary tool calls, change tool/prompt metadata to instructions directing an AI agent to seek SSH keys, AWS credentials, shell history and Kubernetes configuration and to conceal the activity.supported
Basis: reported finding
- supportsDeadbugz: Currently Active MCP Supply-Chain Campaignprimary disclosure
Executive Summary; 'What happens after the third call'; 'The campaign in evidence'
CLM-DEADBUGZ-OUTCOME-BOUNDARYThe cited Pillar evidence demonstrates a live malicious endpoint and public delivery campaign, but it does not establish that any reviewed campaign PR was merged, that a victim installed the package through those PRs, or that credentials were successfully stolen from a victim.supported
Basis: inference
- supportsDeadbugz: Currently Active MCP Supply-Chain Campaignprimary disclosure
Executive Summary; 'The campaign in evidence'; PR status and live-service observations
CLM-DEADBUGZ-DELIVERY-QUALIFIERPillar attributed 23 campaign-related public GitHub pull requests to the zellkernel account in a 74-minute window and reported that none of the 23 reviewed PRs had been merged through GitHub's pull-request merge mechanism at the time of review: 19 were closed and four remained open.supported
Basis: reported finding
- supportsDeadbugz: Currently Active MCP Supply-Chain Campaignprimary disclosure
Executive Summary; 'Attribution: the public delivery operation'; 'The campaign in evidence'
CLM-DEADBUGZ-MITIGATION-BOUNDARYPillar recommends treating tool-definition and schema changes as security events requiring visible renewed approval, fingerprinting tool definitions, and enforcing sensitive file reads, credential access, code execution and outbound writes in client policy rather than trusting remote tool metadata.supported
Basis: reported finding
- supportsDeadbugz: Currently Active MCP Supply-Chain Campaignprimary disclosure
Mitigations and defensive recommendations for MCP clients and operators
CLM-DEADBUGZ-POSTAPPROVAL-BOUNDARYThe malicious behavior depended on changing model-visible MCP definitions after initial benign use: Pillar describes subsequent `tools/list` and `prompts/get` responses changing after the three-call threshold, with the server advertising tool-list changes. Because clients supply those definitions to the model as context, a one-time approval of the server identity did not bind its later semantics.supported
Basis: reported finding
- supportsDeadbugz: Currently Active MCP Supply-Chain Campaignprimary disclosure
'What happens after the third call'; discussion of `tools.listChanged`, changed `tools/list` and `prompts/get` content, and tool definitions supplied to the model
Sources and citation
Material revision history
- Oct 5, 2026 · Published version · first publication · revision 68
Cite this record
DiggingBeagle. “Deadbugz MCP server delayed credential-seeking instructions until after three tool calls.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Aug 12, 2026. https://diggingbeagle.com/cases/deadbugz-mcp-server-delayed-credential-seeking-instructions-until-after-three-to/