Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Medium Severity
Americas
Anguilla
Date OccurredAug 11, 202610:24 UTC
Event TypeCyber Intelligence
SourceTheHackerNews
RecordedAug 11, 2026
Full Description
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instructi