clawsmith.com/signal/mcp-npm-supply-chain-attack
โ IssueUnderservedToolLive
npm Supply Chain Attacks Targeting MCP Packages: Backdoored MCP Servers Exfiltrate Secrets at Scale
Shai-Hulud worm hit 796 npm packages with 132M monthly downloads โ MCP server packages explicitly added to target list. Fake "postmark-mcp" npm package silently BCC'd every email to attacker server for weeks before detection. Shai-Hulud 2.0 compromised Zapier, ENS, PostHog, and Postman packages. MCP servers have deep filesystem access and credential-reading permissions, making them high-value supply chain targets. Installing MCP from third-party marketplaces is now an active attack surface.
Score Breakdown
HN
2,252
Social Proof 1 sources
Gap Assessment
UnderservedExisting solutions leave gaps
MCPShield, Driftcop, mcp-scan exist but none with significant traction. No standardized MCP package signing or provenance verification in place.
Frequently Asked Questions
Virality Score
2,252
across 1 platforms
Details
Signalissue
EcosystemTool
Sources1
Platforms1
Updated2h ago
Trendโ stable
Top ideas
All ideas โRelated signals
All signals โ