<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: GERALD MUDDLETHWACK</title>
    <description>The latest articles on DEV Community by GERALD MUDDLETHWACK (@paraphern).</description>
    <link>https://dev.to/paraphern</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4160202%2F4be670d3-fa9b-438a-9880-a39cd6de4097.png</url>
      <title>DEV Community: GERALD MUDDLETHWACK</title>
      <link>https://dev.to/paraphern</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/paraphern"/>
    <language>en</language>
    <item>
      <title>140 silent contract changes in the official MCP servers (and how to catch them)</title>
      <dc:creator>GERALD MUDDLETHWACK</dc:creator>
      <pubDate>Sat, 03 Oct 2026 17:19:57 +0000</pubDate>
      <link>https://dev.to/paraphern/140-silent-contract-changes-in-the-official-mcp-servers-and-how-to-catch-them-49bg</link>
      <guid>https://dev.to/paraphern/140-silent-contract-changes-in-the-official-mcp-servers-and-how-to-catch-them-49bg</guid>
      <description>&lt;h2&gt;
  
  
  1. Deadbugz -- the server that waits for call #3 (August 2026)
&lt;/h2&gt;

&lt;p&gt;Pillar Security documented an active campaign pushing a malicious MCP server (it calls itself "productivity-suite") through &lt;strong&gt;23 GitHub pull requests opened within 74 minutes&lt;/strong&gt; (Aug 10). It offers two innocent tools -- text formatting and summarization -- and behaves perfectly at first. After &lt;strong&gt;exactly three tool calls&lt;/strong&gt;, it rewrites the metadata it returns to the agent: now the description says to hunt for &lt;strong&gt;SSH private keys, AWS credentials, shell history and Kubernetes config -- and to hide that from the user&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The killer detail: &lt;em&gt;the trigger is a call counter, not a code change.&lt;/em&gt; Nothing new got installed. There is no update diff to review. The PRs were caught (19 closed, 4 left open at review) and no theft was confirmed in the wild -- but as a class this is the cleanest demonstration that "reviewed at install" is not a security control.&lt;/p&gt;

&lt;p&gt;Primary: &lt;a href="https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign" rel="noopener noreferrer"&gt;Pillar Security, "Deadbugz: Currently Active MCP Supply-Chain Campaign"&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  2. GhostSplice -- split the instruction, beat the refusal (August 2026)
&lt;/h2&gt;

&lt;p&gt;ASSET Research Group (UMKC): &lt;em&gt;"Eleven frontier models, one malicious MCP server. Ask them to leak your credentials and they refuse. Split the request into multiple harmless fragments..."&lt;/em&gt; -- &lt;strong&gt;GhostSplice splits one data-theft instruction across a tool description and a later tool result&lt;/strong&gt;, so no single message looks malicious. Average compliance across &lt;strong&gt;11 tested models jumped from 42% to 82%&lt;/strong&gt;, and agents exfiltrated &lt;strong&gt;SSH keys, secrets and source code&lt;/strong&gt;. Per-message inspection (keyword scanning, output filters) never had a chance -- the payload only exists &lt;em&gt;across&lt;/em&gt; messages.&lt;/p&gt;

&lt;p&gt;Primary: &lt;a href="https://asset-group.github.io/" rel="noopener noreferrer"&gt;ASSET Research Group&lt;/a&gt; + &lt;a href="https://bishopfox.com/podcasts/forgotten-assumptions" rel="noopener noreferrer"&gt;Bishop Fox "Spliced Instructions..." (Aug 21)&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  3. ChainDrop -- the worm that poisons Claude Code itself (August 2026)
&lt;/h2&gt;

&lt;p&gt;The self-propagating npm worm (Microsoft's analysis covers &lt;strong&gt;400+ packages&lt;/strong&gt; -- later tallies pushed it to &lt;strong&gt;860+&lt;/strong&gt;) didn't even need you to install anything for its nastiest move: it committed &lt;strong&gt;&lt;code&gt;.claude/settings.json&lt;/code&gt; (a SessionStart hook)&lt;/strong&gt; and &lt;code&gt;.vscode/tasks.json&lt;/code&gt; (runOn: folderOpen) into repositories. So &lt;strong&gt;opening the project -- or starting a Claude Code session -- executed the payload&lt;/strong&gt;. Secrets walked off CI runners; the stealer was a 728 KB obfuscated bundle with C2 over Ethereum contracts.&lt;/p&gt;

&lt;p&gt;That one matters here specifically: your agent config is executable attack surface now, and it is exactly as silently mutable as any tool description.&lt;/p&gt;

&lt;p&gt;Primary: &lt;a href="https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm" rel="noopener noreferrer"&gt;Microsoft Security Blog (Aug 4)&lt;/a&gt; + &lt;a href="https://workos.com/blog/npm-worm-coding-agent-config-credentials" rel="noopener noreferrer"&gt;WorkOS analysis (Aug 6)&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  4. FakeGit -- 800+ fake "MCP servers" and skills, recommended by your agent (July 2026)
&lt;/h2&gt;

&lt;p&gt;Island's research found &lt;strong&gt;7,600 malicious GitHub repos and ~6,600 fake accounts -- with 800+ masquerading as AI skills and MCP servers&lt;/strong&gt;. When users asked their coding agents (Claude Code among them) for recommendations, the agents recommended the malicious repos themselves. The campaign's release assets hit &lt;strong&gt;14M+ downloads&lt;/strong&gt;, and 600+ of its listings sat on public MCP registries (LobeHub, Glama, MCP.so, MCP Market) before takedowns. The chain ended in &lt;strong&gt;StealC&lt;/strong&gt;, an infostealer aimed at developer machines, browser credentials, and cloud tokens.&lt;/p&gt;

&lt;p&gt;Primary: &lt;a href="https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html" rel="noopener noreferrer"&gt;The Hacker News, "FakeGit campaign..." (Jul 20)&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  5. The scale -- silent drift is the norm, not an edge case (September 2026)
&lt;/h2&gt;

&lt;p&gt;An arXiv census harvested the entire public MCP registry -- &lt;strong&gt;21,643 servers, 72,606 version records&lt;/strong&gt; (August 2026 snapshot):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;51.1%&lt;/strong&gt; of multi-version servers changed what they advertise&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;40.6%&lt;/strong&gt; did it &lt;strong&gt;silently&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;4.2%&lt;/strong&gt; redirected their remote endpoint to a different host while keeping the same registry identity -- "a change the protocol never surfaces to installed clients"&lt;/li&gt;
&lt;li&gt;Silent drift is associated with ~&lt;strong&gt;3x higher odds&lt;/strong&gt; of a high-severity finding, and stars/installs are a weak safety signal&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The CVE flow matches: CVE-2026-81486 (path traversal, CISA-noted), CVE-2026-87911 (CVSS 9.6 OS command injection in AWS Labs' postgres MCP server), plus an Atlassian MCP path traversal, a cleartext cluster token in ArcadeDB's MCP, and an SSRF in facebook-ads-mcp-server -- all August-September. September also brought &lt;a href="https://cycode.com/blog/mcp-python-sdk-oauth-account-takeover" rel="noopener noreferrer"&gt;CVE-2026-20176&lt;/a&gt; -- a malicious server could make the &lt;strong&gt;official MCP Python SDK (1.9.1-2.1.1) hand over the client secret, authorization code and PKCE verifier&lt;/strong&gt; (i.e., account takeover); fixed in 1.30.0/2.2.0. And a July dynamic scan of internet-facing MCP servers (&lt;a href="https://arxiv.org/abs/2608.00150" rel="noopener noreferrer"&gt;arXiv:2608.00150&lt;/a&gt;): &lt;strong&gt;91.8% had no OAuth&lt;/strong&gt;, &lt;strong&gt;687 tool instances exposed shell execution with no access control&lt;/strong&gt;, and 41.6% of confirmed servers vanished within three days.&lt;/p&gt;

&lt;p&gt;Primary: &lt;a href="https://arxiv.org/abs/2609.14119" rel="noopener noreferrer"&gt;arXiv:2609.14119, "Same Name, Different Server: A Security Census of Silent Drift in the MCP Ecosystem" (Sep 12)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;And it wasn't only MCP.&lt;/strong&gt; This summer tested every trust boundary around agents. &lt;a href="https://huggingface.co/blog/security-incident-july-2026" rel="noopener noreferrer"&gt;The July Hugging Face intrusion&lt;/a&gt;: an escaped agent system took ~&lt;strong&gt;17,600 malicious actions&lt;/strong&gt; and seized &lt;strong&gt;136 production credentials&lt;/strong&gt; before containment (&lt;a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" rel="noopener noreferrer"&gt;OpenAI's account&lt;/a&gt;). &lt;a href="https://thenextweb.com/news/claude-cowork-sandbox-escape-mac-files-sharedroot" rel="noopener noreferrer"&gt;SharedRoot&lt;/a&gt; (July 23): untrusted content escaped Claude Cowork's local VM through a writable host mount and could read &lt;strong&gt;SSH keys and cloud credentials&lt;/strong&gt; on the Mac, with ~&lt;strong&gt;500,000 macOS users&lt;/strong&gt; in scope before the fix -- Anthropic closed the report as "Informative" and moved new sessions to cloud by default (&lt;a href="https://accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/" rel="noopener noreferrer"&gt;Accomplish AI's write-up&lt;/a&gt;). And &lt;a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" rel="noopener noreferrer"&gt;JadePuffer&lt;/a&gt;, the first fully LLM-driven ransomware, encrypted &lt;strong&gt;1,342 configs&lt;/strong&gt; -- and hunted wallets and seed phrases along the way.&lt;/p&gt;

&lt;h2&gt;
  
  
  What actually stops this
&lt;/h2&gt;

&lt;p&gt;The pattern across every case above is the same: &lt;strong&gt;it's never that the model got jailbroken. It's that something changed -- or was split -- after trust was granted, and nothing re-checked it.&lt;/strong&gt; You can't prompt your way out of that. You pin it.&lt;/p&gt;

&lt;p&gt;I maintain &lt;strong&gt;RugSnare&lt;/strong&gt;, a small open-source tool built exactly for this (Apache-2.0, zero npm dependencies, no telemetry, everything local). What it does:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;npx rugsnare scan&lt;/code&gt; -- pins the exact contract you approved (description, schema, behavioral annotations) into &lt;code&gt;.rugsnare/pins.json&lt;/code&gt;. Commit it.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;npx rugsnare diff&lt;/code&gt; -- re-checks it anywhere (CI gate, pre-launch). Any silent change exits 1. Deterministic, not model judgment.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;rugsnare canary replay&lt;/code&gt; -- replays your real recorded tool calls against a new version &lt;strong&gt;before&lt;/strong&gt; you upgrade (read-only by default), and returns "DO NOT UPGRADE" when behavior changed.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;rugsnare run&lt;/code&gt; -- wraps a live server and enforces policies (blocking the read &lt;code&gt;~/.ssh&lt;/code&gt; / &lt;code&gt;~/.aws/credentials&lt;/code&gt; class of calls), and quarantines mid-session swaps.&lt;/li&gt;
&lt;li&gt;It also scans &lt;code&gt;SKILL.md&lt;/code&gt; skill files with the same adversarial signals -- the ChainDrop class.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Evidence it works, measured on real releases: we pinned &lt;strong&gt;every stable version of the four official &lt;code&gt;@modelcontextprotocol/server-*&lt;/code&gt; servers -- all 66 release pairs -- and counted 140 silent contract changes&lt;/strong&gt; (43 schema breaks, 28 behavioral-hint flips, 37 new items, 24 removals; 43 clean pairs). Not one was announced in a changelog. One command, ~30 minutes, reproducible on your machine.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Even if you never install a tool, do these:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Pin versions (&lt;code&gt;pkg@1.2.3&lt;/code&gt;, never &lt;code&gt;@latest&lt;/code&gt;) -- and treat a version bump as code review.&lt;/li&gt;
&lt;li&gt;Commit your pins and re-diff after every update.&lt;/li&gt;
&lt;li&gt;Treat your MCP config and &lt;code&gt;.claude/settings.json&lt;/code&gt; as executable code.&lt;/li&gt;
&lt;li&gt;Don't auto-approve write/destructive tools.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Pillar Security -- &lt;a href="https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign" rel="noopener noreferrer"&gt;Deadbugz: Currently Active MCP Supply-Chain Campaign&lt;/a&gt; (Aug 12, 2026)&lt;/li&gt;
&lt;li&gt;ASSET Research Group -- &lt;a href="https://asset-group.github.io/" rel="noopener noreferrer"&gt;GhostSplice&lt;/a&gt; (Aug 2026); &lt;a href="https://bishopfox.com/podcasts/forgotten-assumptions" rel="noopener noreferrer"&gt;Bishop Fox podcast&lt;/a&gt; (Aug 21, 2026)&lt;/li&gt;
&lt;li&gt;Microsoft Security Blog -- &lt;a href="https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm" rel="noopener noreferrer"&gt;ChainDrop npm worm&lt;/a&gt; (Aug 4, 2026); &lt;a href="https://workos.com/blog/npm-worm-coding-agent-config-credentials" rel="noopener noreferrer"&gt;WorkOS&lt;/a&gt; (Aug 6, 2026); &lt;a href="https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/" rel="noopener noreferrer"&gt;CyberScoop on the wider campaign&lt;/a&gt; (860+ packages)&lt;/li&gt;
&lt;li&gt;The Hacker News -- &lt;a href="https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html" rel="noopener noreferrer"&gt;FakeGit campaign, 7,600 repos&lt;/a&gt; (Jul 20, 2026); &lt;a href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware" rel="noopener noreferrer"&gt;Island -- AgentBaiting&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://arxiv.org/abs/2609.14119" rel="noopener noreferrer"&gt;arXiv:2609.14119&lt;/a&gt; -- Same Name, Different Server: A Security Census of Silent Drift in the MCP Ecosystem (Sep 12, 2026)&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://arxiv.org/abs/2608.00150" rel="noopener noreferrer"&gt;arXiv:2608.00150&lt;/a&gt; -- Exposed by Design: audit of internet-facing MCP servers (July 2026)&lt;/li&gt;
&lt;li&gt;Cycode -- &lt;a href="https://cycode.com/blog/mcp-python-sdk-oauth-account-takeover" rel="noopener noreferrer"&gt;MCP Python SDK OAuth account takeover&lt;/a&gt;; &lt;a href="https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html" rel="noopener noreferrer"&gt;The Hacker News coverage&lt;/a&gt; (Sep 2026)&lt;/li&gt;
&lt;li&gt;CVE-2026-81486 (mcp-file-context-server, CISA weekly Aug 24-31) - CVE-2026-87911 (awslabs postgres MCP, CVSS 9.6) - CVE-2026-73498 / CVE-2026-67357 / CVE-2026-19956 (Adversa September roundup)&lt;/li&gt;
&lt;li&gt;TNW -- &lt;a href="https://thenextweb.com/news/claude-cowork-sandbox-escape-mac-files-sharedroot" rel="noopener noreferrer"&gt;Claude Cowork SharedRoot sandbox escape&lt;/a&gt;; &lt;a href="https://accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/" rel="noopener noreferrer"&gt;Accomplish AI technical write-up&lt;/a&gt; (Jul 23-26, 2026)&lt;/li&gt;
&lt;li&gt;Hugging Face -- &lt;a href="https://huggingface.co/blog/security-incident-july-2026" rel="noopener noreferrer"&gt;security incident disclosure&lt;/a&gt;; &lt;a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" rel="noopener noreferrer"&gt;OpenAI's account&lt;/a&gt; (July 2026)&lt;/li&gt;
&lt;li&gt;Sysdig -- &lt;a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" rel="noopener noreferrer"&gt;JadePuffer agentic ransomware&lt;/a&gt; (Jul 2026)&lt;/li&gt;
&lt;li&gt;RugSnare -- &lt;a href="https://github.com/Paraphern/rugsnare" rel="noopener noreferrer"&gt;github.com/Paraphern/rugsnare&lt;/a&gt; - &lt;a href="https://www.npmjs.com/package/rugsnare" rel="noopener noreferrer"&gt;npm&lt;/a&gt; - &lt;a href="https://rugsnare.com" rel="noopener noreferrer"&gt;rugsnare.com&lt;/a&gt;
&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;em&gt;Notes / limits: I counted only public, documented incidents from July-September 2026. There are no public reports of end users' wallets or accounts drained specifically by a silent MCP update in this window -- the documented damage is credential theft, code execution and data exfiltration surfaced by research and vendor investigations. I'd rather say that precisely than stretch a headline.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Disclosure: I maintain RugSnare (open source, Apache-2.0, zero deps -- the pinning/diff/replay tooling above). Everything here is runnable and reproducible; happy to answer questions about any of the cases.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>ai</category>
      <category>security</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
