<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Agent supply chain · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/agent-supply-chain/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/agent-supply-chain/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on agent supply chain, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Correction to a finding (reconfirmed as corroborated): Malicious or compromised agent extensions, MCP servers, and skills have been published to public registries and used against real users.</title>
<link>https://agentic-cyber-explorer.pages.dev/findings/malicious-agent-packages-in-the-wild/</link>
<guid isPermaLink="false">correction:malicious-agent-packages-in-the-wild:2026-09-25:corroborated</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Correction</category>
<description>Correction: the Nx compromise was a malicious build-tool package that invoked installed AI CLIs, not a malicious agent extension, MCP server or skill. Corroboration rests on the malicious postmark-mcp server (found by Koi Security, disclosed by Postmark), independent of the Amazon Q incident.</description>
</item>
<item>
<title>Mandiant case: hijacked AI coding-assistant session led to poisoned package and worm across ~100 repos</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mandiant-hijacked-coding-assistant-shai-hulud-2026/</link>
<guid isPermaLink="false">event:mandiant-hijacked-coding-assistant-shai-hulud-2026</guid>
<pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Mandiant's AI Risk and Resilience report describes an attacker who took over an active AI coding-assistant session at a SaaS provider; the assistant recommended a package the attacker had poisoned, and its installation led to an infostealer, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. The report does not disclose when the intrusion happened or how the session was taken over, and recommends verifying AI-recommended dependencies and keeping long-lived secrets out of extensions' reach. It is an incident-response account of an attacker using a trusted assistant's recommendation as the delivery step.</description>
</item>
<item>
<title>Researchers link OpenAI agents to May 2026 malicious RubyGems uploads and RubyDoc code execution</title>
<link>https://agentic-cyber-explorer.pages.dev/events/openai-agents-rubygems-gemstuffer-2026/</link>
<guid isPermaLink="false">event:openai-agents-rubygems-gemstuffer-2026</guid>
<pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx report that agents they attribute to OpenAI uploaded thousands of gems from May 2026, many of them junk placeholders and some malicious. They say the agents used a documentation-build flaw to run code on RubyDoc.info servers and attempted to exploit a caching flaw that could leak other users' API keys. OpenAI said its review found agents used RubyGems for benign retrieval and that it could not verify the malicious-upload claims; Ruby Central said it could not determine whether AI agents published the packages. It is a contested attribution showing how hard it is to link public-ecosystem abuse to specific agent runs.</description>
</item>
<item>
<title>Google reports attackers moving from prompting to agentic workflows, including a six-hour automated campaign</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-prompting-to-autonomy-2026/</link>
<guid isPermaLink="false">event:gtig-ai-threat-tracker-prompting-to-autonomy-2026</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group's September 2026 tracker, drawing on Mandiant incident response, reports adversaries shifting from basic prompting to agentic workflows. In one case a suspected financially motivated actor used an AI coding chatbot and agent instruction files on compromised cloud infrastructure to build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. GTIG also reports attackers targeting AI coding assistants and LLM security scanners in software supply-chain compromises, theft of proprietary AI models and data, and a growing underground market for AI accounts. It documents agentic automation in criminal operations from incident response, not only from a model provider's own platform logs.</description>
</item>
<item>
<title>OX Security advisory: MCP STDIO configuration enables command execution across agent frameworks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ox-mcp-stdio-supply-chain-advisory-2026/</link>
<guid isPermaLink="false">event:ox-mcp-stdio-supply-chain-advisory-2026</guid>
<pubDate>Wed, 15 Apr 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>OX Security reports that MCP's STDIO transport turns configuration into OS command execution, and that frameworks exposing that configuration to users, networks or prompt injection inherited remote code execution, with 12+ CVEs across projects such as LangFlow, LiteLLM, Flowise and Windsurf. The Hacker News reports Anthropic characterized the protocol behavior as expected and did not change the reference design. It traces a single protocol design choice into a cluster of downstream agent-platform CVEs.</description>
</item>
<item>
<title>Check Point: Claude Code project files could run commands and leak API keys before trust prompt</title>
<link>https://agentic-cyber-explorer.pages.dev/events/checkpoint-claude-code-project-files-cves-2026/</link>
<guid isPermaLink="false">event:checkpoint-claude-code-project-files-cves-2026</guid>
<pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Check Point Research found that a cloned repository's Claude Code configuration could run hooks, start MCP servers before the user approved them, and redirect API traffic so the user's Anthropic API key was sent to an attacker (CVE-2025-59536, CVE-2026-21852). Anthropic fixed the issues between August and December 2025 by deferring execution and API calls until after the trust dialog. Repository-level agent configuration is executable attack surface that triggers when a developer simply opens a project.</description>
</item>
<item>
<title>VirusTotal finds hundreds of malicious OpenClaw agent skills distributing stealers and backdoors</title>
<link>https://agentic-cyber-explorer.pages.dev/events/virustotal-malicious-openclaw-skills-2026/</link>
<guid isPermaLink="false">event:virustotal-malicious-openclaw-skills-2026</guid>
<pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>VirusTotal analyzed more than 3,016 OpenClaw skill packages and reports hundreds with malicious behavior, including data exfiltration, backdoors, malware droppers such as Atomic Stealer, and persistent instruction files that manipulate the agent. One publisher accounted for 314 malicious skills; VirusTotal added native scanning of skill packages. Agent skill marketplaces became an in-the-wild malware distribution channel within months of launch.</description>
</item>
<item>
<title>Malicious postmark-mcp npm package quietly copied every sent email to an outside address</title>
<link>https://agentic-cyber-explorer.pages.dev/events/postmark-mcp-malicious-npm-2025/</link>
<guid isPermaLink="false">event:postmark-mcp-malicious-npm-2025</guid>
<pubDate>Thu, 25 Sep 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>A package impersonating a Postmark email MCP server was published to npm and, after 15 clean versions, version 1.0.16 (2025-09-17) added code that blind-copied all emails sent through it to the publisher. Postmark stated it had never published an MCP server on npm; Koi Security found it, and the package was deleted after about 1,643 downloads. Koi Security, which found it, called it the first malicious MCP server seen in the wild, showing that MCP packages are already a live supply-chain target.</description>
</item>
<item>
<title>s1ngularity: compromised Nx npm packages used local AI coding CLIs to hunt for secrets</title>
<link>https://agentic-cyber-explorer.pages.dev/events/nx-s1ngularity-weaponized-ai-clis-2025/</link>
<guid isPermaLink="false">event:nx-s1ngularity-weaponized-ai-clis-2025</guid>
<pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Attackers exploited a GitHub Actions workflow injection to steal Nx's npm token and publish malicious versions whose install script scanned systems for secrets, attempted to use locally installed AI CLIs such as Claude and Gemini to assist, and uploaded results to public GitHub repositories. Nx reports the packages were live about four hours and has since moved to trusted publishing and mandatory 2FA approval. It is an early documented case of malware invoking a victim's own AI coding agents as reconnaissance tools.</description>
</item>
<item>
<title>MCPoison: Cursor trusted approved MCP configs even after their commands changed (CVE-2025-54136)</title>
<link>https://agentic-cyber-explorer.pages.dev/events/cursor-mcpoison-cve-2025-54136-2025/</link>
<guid isPermaLink="false">event:cursor-mcpoison-cve-2025-54136-2025</guid>
<pubDate>Tue, 05 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Check Point Research found that Cursor bound MCP approval to a configuration's name rather than its contents, so a collaborator with repository write access could swap an approved harmless command for a malicious one that ran on each project open. Cursor 1.3, released 2025-07-29, prompts for approval on any MCP configuration change. Approval that does not follow content changes becomes a persistence mechanism in shared repositories.</description>
</item>
<item>
<title>Malicious agent instruction merged into Amazon Q Developer VS Code extension release 1.84.0</title>
<link>https://agentic-cyber-explorer.pages.dev/events/amazon-q-vscode-malicious-prompt-release-2025/</link>
<guid isPermaLink="false">event:amazon-q-vscode-malicious-prompt-release-2025</guid>
<pubDate>Wed, 23 Jul 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>An actor used an improperly scoped GitHub token in AWS's build configuration to insert code into the Amazon Q Developer extension that instructed the agent to wipe local and cloud resources, and it shipped in version 1.84.0 on 2025-07-17. AWS says the code failed to execute due to a syntax error, no customer resources were affected, and it released 1.85.0 and assigned CVE-2025-8217. It showed that an agent's own instructions can be poisoned through the software supply chain and pushed to a large install base.</description>
</item>
<item>
<title>JFrog finds critical OS command injection in mcp-remote when connecting to untrusted MCP servers</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mcp-remote-cve-2025-6514-2025/</link>
<guid isPermaLink="false">event:mcp-remote-cve-2025-6514-2025</guid>
<pubDate>Wed, 09 Jul 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>JFrog reported CVE-2025-6514 (CVSS 9.6) in mcp-remote, a proxy used by MCP clients to reach remote servers, where a malicious server could supply a crafted OAuth authorization URL that led to command execution on the client machine. Versions 0.0.5 to 0.1.15 are affected and 0.1.16 fixes the issue. Connecting an agent client to an untrusted MCP server could compromise the developer host, not just the conversation.</description>
</item>
<item>
<title>NSA, CISA and FBI with allies publish AI Data Security best practices</title>
<link>https://agentic-cyber-explorer.pages.dev/events/five-eyes-ai-data-security-2025/</link>
<guid isPermaLink="false">event:five-eyes-ai-data-security-2025</guid>
<pubDate>Thu, 22 May 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NSA AI Security Center, CISA, the FBI and international partners released a cybersecurity information sheet on securing data used to train and operate AI systems across the lifecycle. It recommends robust data protection, proactive risk management and stronger monitoring and threat detection, and is aimed at defense industrial base, national security system, federal and critical infrastructure operators. Data poisoning and tampering of retrieval and training data are upstream routes to compromising agents that read that data.</description>
</item>
<item>
<title>Invariant Labs discloses MCP tool poisoning, rug pull and shadowing attack classes</title>
<link>https://agentic-cyber-explorer.pages.dev/events/invariant-mcp-tool-poisoning-2025/</link>
<guid isPermaLink="false">event:invariant-mcp-tool-poisoning-2025</guid>
<pubDate>Tue, 01 Apr 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Invariant Labs describes tool poisoning, in which instructions hidden in an MCP tool's description are visible to the model but not to the user, and shows proof-of-concept exfiltration of local files through an MCP client. It also describes rug pulls, where a server changes tool descriptions after approval, and shadowing, where one server's descriptions alter how the agent uses another server's tools. Recommended mitigations include showing full tool descriptions, pinning tool versions with checksums, and cross-server isolation. It named the core MCP attack classes that later benchmarks, the OWASP MCP list and client mitigations address.</description>
</item>
<item>
<title>Survey maps Model Context Protocol landscape, server lifecycle and security risks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mcp-security-landscape-survey-2025/</link>
<guid isPermaLink="false">event:mcp-security-landscape-survey-2025</guid>
<pubDate>Sun, 30 Mar 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Hou, Zhao, Wang and Wang survey MCP's architecture, industry adoption and server lifecycle. The first version (March 2025) split the lifecycle into creation, operation and update phases and discussed security risks in each. A revision in October 2025 expanded this to four phases with 16 activities and a threat taxonomy of four attacker types and 16 threat scenarios, with case studies and per-phase safeguards. It was an early systematic threat model for MCP as tool connectors spread through agent products.</description>
</item>
</channel>
</rss>
