Severity: CriticalAdvisorySupply chain
Popular MCP server turns malicious in a point release (rug pull)
Global
Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.
A widely installed community MCP server shipped a minor update that added covert data-collection logic to a previously benign file tool. Because most deployments had auto-approval enabled, the malicious version propagated before maintainers pulled it.
What to do
Pin versions and verify cryptographic integrity before upgrading, disable auto-approval for tool updates, and diff server behaviour against the previously trusted release.
Mapped framework pillars
Sources
#rug pull#supply chain#auto-approval
