The Model Context Protocol is becoming the HTTP of AI integration. Every major agent framework uses it. MCP servers connect LLMs to databases, APIs, email services, file systems - anything the model needs to act on. The security model around these servers is roughly where npm was in 2014: install what you want, trust the metadata, hope nobody's lying.
On February 2, Koi Security published an audit of 2,857 skills on ClawHub, the package registry for the OpenClaw agent framework. They found 341 malicious skills, 335 of them delivering Atomic Stealer, a commodity macOS infostealer, through skills masquerading as crypto trading tools. The attack chain uses typosquatting, fake prerequisites, and social engineering to get users to execute shell commands that exfiltrate wallet keys, SSH credentials, and browser passwords. That's 12% of audited packages confirmed malicious, and this was one research team's first pass at one registry.
This is not novel. It is npm's left-pad era with higher stakes, because MCP servers execute with the privileges of the agent, and agents increasingly act on behalf of users. OWASP published a Top 10 specifically for MCP. Supply chain attacks are #4. Tool poisoning - where an attacker manipulates tool metadata to redirect agent behavior - is #3. If your organization uses MCP servers, apply the same SCA discipline you'd apply to npm: pin versions, audit dependencies, run a registry allowlist, and assume every unvetted tool is hostile until proven otherwise.
The Attack Surface in Practice
The ClawHub audit is the largest confirmed incident, but the pattern started earlier.
In September 2025, Semgrep documented the first malicious MCP server on npm: a package called postmark-mcp, a typosquat of the Postmark email service. It maintained 15 clean versions under an active developer account before adding a single line of code - a BCC on every email sent through the agent to the attacker's address. No malware, no obfuscation. Patient social engineering of the trust model.
In October 2025, JFrog disclosed CVE-2025-6515 in oatpp-mcp: a prompt hijacking attack where an attacker who obtains a valid session ID can inject responses into a victim's active connection. The attacker sprays messages with low event numbers until one is accepted by the client. If the malicious event processes, the client executes poisoned prompts.
The Koi Security findings from February show the threat scaling from targeted attacks to bulk campaigns. All 335 Atomic Stealer skills shared the same C2 infrastructure at 91.92.242[.]30. The typosquats were deliberate: clawhub, clawhub1, clawhubb, clawhubcli, clawwhub, cllawhub. Six additional skills hid reverse shell backdoors inside functional code or exfiltrated bot credentials to webhook endpoints.
Why This Is Worse Than npm
npm supply chain attacks compromise a build pipeline or a running application. MCP supply chain attacks compromise an autonomous agent acting with delegated user privileges. The blast radius is different:
- A poisoned npm package in a CI pipeline can exfiltrate environment variables. A poisoned MCP tool can instruct the agent to read your email, modify your repository, or send messages on your behalf.
- npm attacks require the developer to install the package. MCP attacks can use tool poisoning through metadata alone - the tool description tells the agent what to do, and a malicious description redirects behavior without modifying code.
- MCP servers often run with broad filesystem and network access. The protocol's default posture is permissive.
The OWASP MCP Top 10 captures this escalation. Token mismanagement (#1), privilege escalation via scope creep (#2), and tool poisoning (#3) are the top three risks. All three reflect a protocol designed for capability first and security second.
Sources: