Evidence · DiggingBeagle record
Deadbugz: Currently Active MCP Supply-Chain Campaign
Pillar Security research on the productivity-suite MCP campaign: a benign-looking server returned ordinary tools initially, then after three tool calls changed metadata presented to the agent to seek credentials and sensitive local configuration.
- Published
- Aug 12, 2026
- Source role
- primary disclosure
Evidence record
Pillar Security research on the productivity-suite MCP campaign: a benign-looking server returned ordinary tools initially, then after three tool calls changed metadata presented to the agent to seek credentials and sensitive local configuration.
Claim-level citations (5)
- supportsDeadbugz MCP server delayed credential-seeking instructions until after three tool calls: Pillar observed productivity-suite return benign MCP behavior initially and, after three ordinary tool calls, change tool/prompt metadata to instructions directing an AI agent to seek SSH keys, AWS credentials, shell history and Kubernetes configuration and to conceal the activity.
Executive Summary; 'What happens after the third call'; 'The campaign in evidence'
- supportsDeadbugz MCP server delayed credential-seeking instructions until after three tool calls: The cited Pillar evidence demonstrates a live malicious endpoint and public delivery campaign, but it does not establish that any reviewed campaign PR was merged, that a victim installed the package through those PRs, or that credentials were successfully stolen from a victim.
Executive Summary; 'The campaign in evidence'; PR status and live-service observations
- supportsDeadbugz MCP server delayed credential-seeking instructions until after three tool calls: Pillar attributed 23 campaign-related public GitHub pull requests to the zellkernel account in a 74-minute window and reported that none of the 23 reviewed PRs had been merged through GitHub's pull-request merge mechanism at the time of review: 19 were closed and four remained open.
Executive Summary; 'Attribution: the public delivery operation'; 'The campaign in evidence'
- supportsDeadbugz MCP server delayed credential-seeking instructions until after three tool calls: Pillar recommends treating tool-definition and schema changes as security events requiring visible renewed approval, fingerprinting tool definitions, and enforcing sensitive file reads, credential access, code execution and outbound writes in client policy rather than trusting remote tool metadata.
Mitigations and defensive recommendations for MCP clients and operators
- supportsDeadbugz MCP server delayed credential-seeking instructions until after three tool calls: The malicious behavior depended on changing model-visible MCP definitions after initial benign use: Pillar describes subsequent `tools/list` and `prompts/get` responses changing after the three-call threshold, with the server advertising tool-list changes. Because clients supply those definitions to the model as context, a one-time approval of the server identity did not bind its later semantics.
'What happens after the third call'; discussion of `tools.listChanged`, changed `tools/list` and `prompts/get` content, and tool definitions supplied to the model
Cite this record
DiggingBeagle. “Deadbugz: Currently Active MCP Supply-Chain Campaign.” Published Aug 12, 2026. https://diggingbeagle.com/sources/deadbugz-currently-active-mcp-supply-chain-campaign/