Most teams vet an MCP server once: someone reads the tool list, tries it, and approves it. Deadbugz was built to pass exactly that check.

What happened

Pillar Security tracked a campaign that pushed a server called productivity-suite through 23 unsolicited GitHub pull requests to unrelated AI, MCP and developer-tool repositories. All 23 were opened within 74 minutes on 10 August 2026. The server offered text formatting and summarisation tools and behaved as advertised on its first calls.

After exactly three tool calls, it changed the metadata it returned into instructions for the agent: find SSH private keys, AWS credentials, shell history and Kubernetes configuration, and hide the activity from the user. Pillar confirmed the three-call trigger and the altered metadata from public sources. The write-up does not document confirmed credential theft in the wild.

Treat tool-definition changes after approval as security events requiring re-authorization.

Pillar Security, recommended mitigation (paraphrased)

The lesson: approval at install time is a snapshot

The trigger was a call count, not a code change. Nothing new was installed, and there was no update to review. Any control that only looks at the tool when it is added will see a clean tool. The only place to catch this is where the agent acts on the new instructions: when it tries to read a key, run a command or send data out.

Deadbugz is not the only MCP concern this season. Adversa's September roundup also lists three MCP server CVEs from August: a path traversal in an Atlassian MCP server (CVE-2026-73498), a cluster token exposed in cleartext by an ArcadeDB MCP server (CVE-2026-67357) and a server-side request forgery flaw in facebook-ads-mcp-server (CVE-2026-19956).

Runtime policy: what the agent is allowed to do, whoever told it

DarkControl doesn't try to judge whether a tool description is honest. It governs what the agent then does on the endpoint:

  • Deny shell commands that read credential stores, such as ~/.ssh, ~/.aws/credentials, ~/.kube/config and shell history files, unless a specific workflow needs them.
  • Deny or ask for outbound network calls to destinations that are not on your allowlist, which is how collected secrets would leave the machine.
  • Unmatched actions default to ask, so new behaviour from a changed tool reaches a human instead of running silently.
  • The immutable audit log shows the whole sequence of actions, so you can see when an agent's behaviour changed and which session it happened in.

Sources: Pillar Security, 'Deadbugz: Currently Active MCP Supply-Chain Campaign': https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign · Adversa AI, 'MCP security September 2026': https://adversa.ai/blog/top-mcp-security-resources-september-2026/


See which credentials and destinations your agents touch today. DarkControl's free 7-day watch-only audit covers up to 10 devices, with no credit card.

Book a demo