Tech
Malicious MCP Servers: What Deadbugz Taught Us About Auditing Our AI Agent Setup
On the evening of August 10, 2026, a single GitHub account opened 23 pull requests against unrelated AI and developer-tool projects in 74 minutes. Each one added an MCP server called productivity-suite to the project's config. It offered text formatting and summarization, and for the first three tool calls that is all it did. After the third call it changed the instructions it sent back to the AI agent, telling it to look for SSH keys, AWS credentials, shell history and Kubernetes config, and ...
Read the full discussion on Dev.to
This article was aggregated from Dev.to. Click to join the conversation.
View on Dev.to