Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can w
Original Disclosure
https://thehackernews.com/2026/08/malicious-mcp-servers-can…
Severity
medium
Sector
other
Disclosure date
August 11, 2026
Indexed
13 hours, 33 minutes ago