Skip to content
Now taking design partners.Roadmap →

Campaigns

The morning an agent or MCP incident drops, you don't need a dashboard. You need a plan.

A malicious MCP server ships. An inference gateway lands on CISA KEV. A model on the hub turns out to carry a payload. Campaigns are named, targeted, fleet-wide sweeps launched on a catalog event, across laptops and servers at once. Online hosts pick one up within a minute; offline hosts pick it up on their next check-in. The classic package and extension incidents run through the same machinery, the base layer never went away.

Newest brief:LiteLLM MCP command injection (CVE-2026-42271, CISA KEV)· 38d agotarget < 4h at GA

Incident response

Campaign response in 30 minutes.

The morning an agent or MCP incident drops, you don't need another dashboard. You need the exposed-host list and a plan.

  1. 01T+00:00

    Catalog entry lands

    Malicious MCP published. Signed entry, campaign ready.

  2. 02T+04:00

    You launch it

    One click. Every host, laptops and servers.

  3. 03T+14:00

    Fleet reports in

    Live count. Target: 95% of 1,000 hosts in ten minutes.

  4. 04T+30:00

    Exposed list, rotation plan

    Who's hit, what it could reach, what to rotate.

How templates arrive: Templates ship signed with the threat catalog and are added as we write incidents up, without an agent release. The library on /campaigns-library is our published research on what is worth sweeping for.

Bundled templates

The incidents we have written up as campaign templates.

Our published research on the incidents worth sweeping for. The agent and model incidents lead; the npm and extension waves are the supply-chain base underneath. Templates ship signed with the catalog, and the catalog is still filling out, so treat this library as the research rather than a shipped inventory count.

ai_agent · 2026

Amazon Q workspace config exfil

Amazon Q Developer auto-loaded a malicious MCP config committed into a repository (CVE-2026-12957, CVSS 8.5, disclosed by Wiz). The spawned commands inherited the developer's environment, exfiltrating live AWS credentials with no prompt.

AWS credentials in the workspace

ai_agent · 2026

Hugging Face agentic infrastructure breach

An autonomous AI agent breached Hugging Face production infrastructure, executing over 17,000 logged actions and reaching internal datasets and service credentials. Disclosed 16 July 2026. A separate incident from the 2024 backdoored-models research.

Internal datasets + service credentials

ai_agent · 2026

JadePuffer

Ransomware executed end to end by an AI agent rather than a human operator, documented by Sysdig. Entry was an exposed Langflow instance carrying CVE-2025-3248; it encrypted 1,342 Nacos configuration items.

Exposed Langflow instances

mcp · 2026

MCP stdio transport RCE

Remote code execution through the MCP stdio transport, documented by OX Security across Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI. Windsurf (CVE-2026-30615) needed no user interaction. Anthropic says the execution model is by design.

Cursor · VS Code · Windsurf · Claude Code

mcp · 2025

postmark-mcp

A malicious version of an MCP server (postmark-mcp) was documented in the wild in September 2025. The compromised release silently BCC'd every outbound email to an attacker-controlled address.

In-the-wild MCP compromise, BCC exfiltration pattern

hugging face · 2024

Hugging Face malicious models

JFrog researchers identified roughly 100 malicious models hosted on Hugging Face in February 2024. About 25 of them delivered unsafe-deserialisation payloads that executed on model load via Python's pickle __reduce__ path.

~100 backdoored models, ~25 unsafe-deserialisation payloads

pypi · 2026

LiteLLM MCP RCE

Command injection in LiteLLM's MCP test endpoints (CVE-2026-42271, CVSS 8.7). On CISA KEV since 8 June 2026, exploited in the wild, and chainable to unauthenticated RCE. A successful call exposes every model-provider key the proxy holds.

Every provider key behind the proxy

npm · 2025

chalk · debug takeover

The maintainer of chalk, debug and 16 other npm libraries had accounts compromised via targeted phishing on Sept 8 2025. Malicious versions were live on the registry for roughly two hours.

18 packages, 2.6B weekly downloads reach

vs code + openvsx · 2025

GlassWorm

Self-propagating worm across the VS Code Marketplace and OpenVSX extension registries. Koi Security disclosed on October 18 2025. Signature traits are invisible-Unicode obfuscation and Solana blockchain C2.

35,800 installs, self-propagating VS Code + OpenVSX worm

npm · 2025

Shai-Hulud 2.0

Second wave of the Shai-Hulud npm worm. 796 packages backdoored via stolen maintainer credentials, self-propagates through the same postinstall pattern as wave 1.

796 npm packages, self-replicating worm

chrome + edge · 2024

Cyberhaven wave

Christmas Eve 2024. An attacker phished a Cyberhaven employee's Chrome Web Store credential and pushed a malicious update. 34 further extensions from the same campaign were identified over the following weeks.

35 extensions, 2.6M users, 400K on Cyberhaven itself