Case · DiggingBeagle record

Deadbugz MCP server delayed credential-seeking instructions until after three tool calls

Deadbugz was a live malicious MCP delivery campaign and post-approval semantic-mutation technique, not a confirmed credential-theft victim incident. Pillar observed a remote `productivity-suite` service that behaved benignly for three ordinary calls and then changed model-visible tool and prompt metadata to seek SSH keys, AWS credentials, shell history and Kubernetes configuration while concealing the activity. The same server identity therefore acquired new semantics after initial trust. All 23 reviewed campaign pull requests were unmerged at review time, so the cited evidence establishes the malicious service, delivery campaign and evasion mechanism but not a victim installation, realized credential access or loss.

Assessment profile

Assessment method
Setting
production
Exploitation
observed live
Evidence
Grade B
Remediation
mitigation available
Basis and provenance

The malicious MCP service and delivery campaign were observed live and technically characterized, including the delayed metadata change. Public evidence in the focal source does not establish victim installation or realized credential theft, so impact is left unbanded.

Assessed Oct 5, 2026 using diggingbeagle.assessment/1.

Timeline

  1. Aug 10, 2026
    Event type unspecified

    Campaign account opened 23 delivery pull requests

    Pillar reports 23 campaign-related GitHub pull requests created in roughly 74 minutes; the reviewed PRs were 19 closed and four still open, with none merged through the GitHub PR mechanism at review time.

  2. Aug 12, 2026
    disclosure

    Pillar disclosed the live three-call MCP mutation campaign

    Pillar published its analysis of the live `productivity-suite` endpoint, delayed metadata mutation and public delivery activity.

Claims & evidence

CLM-DEADBUGZ-RUNTIME-GATEPillar observed productivity-suite return benign MCP behavior initially and, after three ordinary tool calls, change tool/prompt metadata to instructions directing an AI agent to seek SSH keys, AWS credentials, shell history and Kubernetes configuration and to conceal the activity.supported

Basis: reported finding

Link to claim
CLM-DEADBUGZ-OUTCOME-BOUNDARYThe cited Pillar evidence demonstrates a live malicious endpoint and public delivery campaign, but it does not establish that any reviewed campaign PR was merged, that a victim installed the package through those PRs, or that credentials were successfully stolen from a victim.supported

Basis: inference

Link to claim
CLM-DEADBUGZ-DELIVERY-QUALIFIERPillar attributed 23 campaign-related public GitHub pull requests to the zellkernel account in a 74-minute window and reported that none of the 23 reviewed PRs had been merged through GitHub's pull-request merge mechanism at the time of review: 19 were closed and four remained open.supported

Basis: reported finding

Link to claim
CLM-DEADBUGZ-MITIGATION-BOUNDARYPillar recommends treating tool-definition and schema changes as security events requiring visible renewed approval, fingerprinting tool definitions, and enforcing sensitive file reads, credential access, code execution and outbound writes in client policy rather than trusting remote tool metadata.supported

Basis: reported finding

Link to claim
CLM-DEADBUGZ-POSTAPPROVAL-BOUNDARYThe malicious behavior depended on changing model-visible MCP definitions after initial benign use: Pillar describes subsequent `tools/list` and `prompts/get` responses changing after the three-call threshold, with the server advertising tool-list changes. Because clients supply those definitions to the model as context, a one-time approval of the server identity did not bind its later semantics.supported

Basis: reported finding

Link to claim

Sources and citation

Material revision history

  1. Oct 5, 2026 · Published version · first publication · revision 68

Cite this record

DiggingBeagle. “Deadbugz MCP server delayed credential-seeking instructions until after three tool calls.” Published by DiggingBeagle Oct 5, 2026 · Public disclosure Aug 12, 2026. https://diggingbeagle.com/cases/deadbugz-mcp-server-delayed-credential-seeking-instructions-until-after-three-to/

Citation guidance