DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Deadbugz: Currently Active MCP Supply-Chain Campaign

Quality: 9/10 Relevance: 9/10

Summary

Pillar Security details an active Deadbugz MCP supply-chain campaign that injects malicious metadata into MCP tool definitions after three calls, enabling credential theft and stealthy operations. The report provides indicators of compromise, attribution to the zellkernel account, delivery methods via GitHub pull requests, and actionable remediation steps for developers and MCP platform builders.

🚀 Service construit par Johan Denoyer