Campaigns
The morning an agent or MCP incident drops, you don't need a dashboard. You need a plan.
A malicious MCP server ships. An inference gateway lands on CISA KEV. A model on the hub turns out to carry a payload. Campaigns are named, targeted, fleet-wide sweeps launched on a catalog event, across laptops and servers at once. Online hosts pick one up within a minute; offline hosts pick it up on their next check-in. The classic package and extension incidents run through the same machinery, the base layer never went away.
Incident response
Campaign response in 30 minutes.
The morning an agent or MCP incident drops, you don't need another dashboard. You need the exposed-host list and a plan.
- 01T+00:00
Catalog entry lands
Malicious MCP published. Signed entry, campaign ready.
- 02T+04:00
You launch it
One click. Every host, laptops and servers.
- 03T+14:00
Fleet reports in
Live count. Target: 95% of 1,000 hosts in ten minutes.
- 04T+30:00
Exposed list, rotation plan
Who's hit, what it could reach, what to rotate.
Bundled templates
The incidents we have written up as campaign templates.
Our published research on the incidents worth sweeping for. The agent and model incidents lead; the npm and extension waves are the supply-chain base underneath. Templates ship signed with the catalog, and the catalog is still filling out, so treat this library as the research rather than a shipped inventory count.
ai_agent · 2026
Amazon Q workspace config exfil
Amazon Q Developer auto-loaded a malicious MCP config committed into a repository (CVE-2026-12957, CVSS 8.5, disclosed by Wiz). The spawned commands inherited the developer's environment, exfiltrating live AWS credentials with no prompt.
AWS credentials in the workspace
ai_agent · 2026
Hugging Face agentic infrastructure breach
An autonomous AI agent breached Hugging Face production infrastructure, executing over 17,000 logged actions and reaching internal datasets and service credentials. Disclosed 16 July 2026. A separate incident from the 2024 backdoored-models research.
Internal datasets + service credentials
ai_agent · 2026
JadePuffer
Ransomware executed end to end by an AI agent rather than a human operator, documented by Sysdig. Entry was an exposed Langflow instance carrying CVE-2025-3248; it encrypted 1,342 Nacos configuration items.
Exposed Langflow instances
mcp · 2026
MCP stdio transport RCE
Remote code execution through the MCP stdio transport, documented by OX Security across Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI. Windsurf (CVE-2026-30615) needed no user interaction. Anthropic says the execution model is by design.
Cursor · VS Code · Windsurf · Claude Code
mcp · 2025
postmark-mcp
A malicious version of an MCP server (postmark-mcp) was documented in the wild in September 2025. The compromised release silently BCC'd every outbound email to an attacker-controlled address.
In-the-wild MCP compromise, BCC exfiltration pattern
hugging face · 2024
Hugging Face malicious models
JFrog researchers identified roughly 100 malicious models hosted on Hugging Face in February 2024. About 25 of them delivered unsafe-deserialisation payloads that executed on model load via Python's pickle __reduce__ path.
~100 backdoored models, ~25 unsafe-deserialisation payloads
pypi · 2026
LiteLLM MCP RCE
Command injection in LiteLLM's MCP test endpoints (CVE-2026-42271, CVSS 8.7). On CISA KEV since 8 June 2026, exploited in the wild, and chainable to unauthenticated RCE. A successful call exposes every model-provider key the proxy holds.
Every provider key behind the proxy
npm · 2025
chalk · debug takeover
The maintainer of chalk, debug and 16 other npm libraries had accounts compromised via targeted phishing on Sept 8 2025. Malicious versions were live on the registry for roughly two hours.
18 packages, 2.6B weekly downloads reach
vs code + openvsx · 2025
GlassWorm
Self-propagating worm across the VS Code Marketplace and OpenVSX extension registries. Koi Security disclosed on October 18 2025. Signature traits are invisible-Unicode obfuscation and Solana blockchain C2.
35,800 installs, self-propagating VS Code + OpenVSX worm
npm · 2025
Shai-Hulud 2.0
Second wave of the Shai-Hulud npm worm. 796 packages backdoored via stolen maintainer credentials, self-propagates through the same postinstall pattern as wave 1.
796 npm packages, self-replicating worm
chrome + edge · 2024
Cyberhaven wave
Christmas Eve 2024. An attacker phished a Cyberhaven employee's Chrome Web Store credential and pushed a malicious update. 34 further extensions from the same campaign were identified over the following weeks.
35 extensions, 2.6M users, 400K on Cyberhaven itself