Skip to content
The Nexus
SECURITYAug 11 · 10:24 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Malicious MCP Servers connected to an AI coding assistant pose a threat by allowing data exfiltration without requiring one obviously harmful instruction. The attack targets sensitive information, including SSH keys, source code, environment secrets, and customer data. To bypass defenses, the malicious tool splits requests into fragments that appear routine and places them in channels already used by the assistant.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting