18 Malicious npm Packages Found Hijacking AI Coding Agents via Remote Commands
Security researchers building a public advisory database for the Model Context Protocol (MCP) identified 19 malicious npm packages capable of remotely controlling AI coding agents such as Claude. As of the article's publication date, 18 of the 19 packages remained downloadable from the public npm registry, with only one — anthropic-setup — having been taken down. The packages work by opening outbound WebSocket connections or polling remote HTTPS endpoints, allowing attackers to issue commands directly to an already-authenticated AI agent on the victim's machine, bypassing typical firewall protections. Some packages went further, intercepting API keys, replacing legitimate binaries, or registering rogue MCP servers into developer tool configurations without obvious signs of tampering. Researchers attribute the broad attack surface to the copy-paste nature of MCP server configuration, live tool-definition fetching, and the lack of package provenance or signature verification in the current AI-agent ecosystem.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in