Skip to content
The Injection_
LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

Category

Supply chain

Skills, MCP servers, plugins, packages and models that ship risk.

Incident feed

5 of 5 · newest first
  1. CVE-2026-104850HIGHVulnerabilityModel Context ProtocolMCP TypeScript SDK: OAuth client could leak credentials to serversCVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client's OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.
  2. AIR SecurityAnthropic skill scanner bypassed: malicious skills marked safeMEDAttackAIR SecurityAnthropic skill scanner bypassed: malicious skills marked safeAIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.
  3. MemoryOS (PyPI)MemTensor MemOS packages compromised with a credential stealerHIGHSupply chainSocketMemTensor MemOS packages compromised with a credential stealerMalicious releases of MemTensor's MemOS packages on npm and PyPI shipped sckit, a Go credential stealer that runs on import and sends npm, PyPI, GitHub, cloud and SSH secrets to skyleen[.]fr. Safe versions: npm 0.1.20, PyPI 2.0.33.
  4. Claude CodePlugin4Shell: zero-click plugin RCE in four AI coding agentsHIGHVulnerabilityAIR SecurityPlugin4Shell: zero-click plugin RCE in four AI coding agentsPlugin4Shell is a zero-click remote code execution flaw in how Claude Code, Codex, GitHub Copilot and Gemini CLI install pinned plugins. AIR says Claude Code and Codex are fixed, Copilot is not, and Gemini CLI will not be patched.
  5. AIR SecurityMCPJacking: 155 hijackable servers in the official MCP registryHIGHSupply chainAIR SecurityMCPJacking: 155 hijackable servers in the official MCP registryMCPJacking is an attack on MCP registry entries whose domains have expired. AIR Security found 155 such servers in the official MCP registry, re-registered the domains and gained remote prompt execution on agents that trusted them.