Skip to main content

An unreviewed MCP config edit gave attackers OS-level access to 73 repos, including one of Microsoft's own

0
Medium
Published: 09/13/2026 (09/13/2026, 19:19:20 UTC)
Source: Reddit BlueTeam

Description

A campaign named Miasma exploited a vulnerability in the Model Context Protocol (MCP) tool configuration process to gain OS-level access to 73 GitHub repositories, including one owned by Microsoft Azure. The attack leverages the fact that MCP clients trust tool descriptions as executable instructions without re-prompting or sandboxing, allowing malicious edits to MCP config files to run with developer privileges. This attack class, known as MCP tool poisoning, was first documented in 2025 and escalated to real-world exploitation by mid-2026. The campaign abused the approval process tied to server names rather than content, enabling malicious commands to execute automatically after initial approval. OWASP ranks this attack third in its MCP Top 10 threats. Mitigations include rigorous code review of MCP config changes, pinning tool definitions, scoping privileges per tool, maintaining allowlists of MCP servers, and sandboxing agent execution.

Reddit Discussion

r/AskNetsec·posted by u/Efficient-Web-8065
00

In June, a group tracked as TeamPCP/UNC6780 planted malicious MCP configuration files across 73 GitHub repos, one of them belonging to Azure.

The mechanism was almost dumb in its simplicity. Several popular IDEs, Cursor, Claude Code, Gemini CLI, GitHub Copilot, and Amazon Q were all named in the disclosures, bind their "approve this MCP server" prompt to the server's name, not its actual contents. Approve a project's .mcp.json once, and any later edit to that file, including a swapped-in malicious command, runs automatically with the developer's own OS-level privileges. No re-prompt. No sandbox. No second look.

Six months from the first disclosure of tool poisoning as a technique to a working worm compromising a major vendor's own repo.

I wrote up the full attack taxonomy (tool poisoning, shadowing, rug pulls, parasitic tool chains) plus the incident timeline (CVEs, the OX Security disclosure, Microsoft's June 30 writeup, OWASP now ranking it #3 on the MCP Top 10): https://blog.defensify.in/mcp-tool-poisoning-attack-guide/

Curious if anyone here has caught this in the wild or built detection for it.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 12:17:17 UTC

Technical Analysis

MCP tool poisoning is an attack where malicious instructions are embedded in the tool descriptions returned by MCP servers to clients. Since MCP clients interpret these descriptions as executable instructions without re-prompting or sandboxing, attackers can inject commands that run with the developer's OS-level privileges. The Miasma campaign, attributed to TeamPCP/UNC6780, planted adversarial MCP configuration files across 73 GitHub repositories, including Microsoft Azure's. The attack exploits the approval mechanism that binds trust to server names rather than the actual content of MCP config files, allowing swapped-in malicious commands to execute automatically. This vulnerability was preceded by CVEs exposing authentication gaps and command injection in MCP components. OWASP ranks tool poisoning as a top MCP threat. Mitigations involve treating MCP config changes as code reviews, pinning tool definitions, scoping privileges, allowlisting MCP servers, and sandboxing agent execution.

Potential Impact

Attackers gained OS-level access to 73 GitHub repositories, including a Microsoft Azure repository, by exploiting the trust model in MCP tool descriptions. This allowed execution of arbitrary commands with developer privileges without additional prompts or sandboxing, potentially leading to unauthorized code execution, data exfiltration, and supply chain compromise. The attack bypasses typical prompt injection defenses and can chain multiple tools to escalate privileges or exfiltrate data stealthily. The widespread use of MCP SDKs and clients means a large attack surface with over 200,000 vulnerable instances and 150 million downloads of affected libraries.

Defensive Guidance

Microsoft's guidance treats MCP tool descriptions as supply-chain assets requiring the same review rigor as production code. Organizations should treat every MCP config change as a code review event, not just the initial approval. Pin tool definitions by hashing or version-locking to detect unauthorized changes and prevent rug pulls. Scope privileges per tool to limit capabilities and prevent parasitic tool chains. Maintain explicit allowlists of MCP servers and be cautious of third-party servers with broad tool surfaces. Manual testing for tool poisoning is recommended, as automated filters have low refusal rates. Sandboxing agent execution is advised to contain potential damage. These mitigations address the root causes of the attack and reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa7e5be55bf5e2cf508ba03

Added to database: 09/14/2026, 12:17:02 UTC

Last enriched: 09/14/2026, 12:17:17 UTC

Last updated: 09/15/2026, 05:01:31 UTC

Views: 41

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses