Researchers reported a supply-chain campaign in which SmartLoader operators cloned a legitimate Oura MCP Server project (used to connect AI assistants to Oura Ring health data) and used a deceptive GitHub ecosystem to distribute a trojanized version that installs the StealC information stealer. The operation relied on fake GitHub accounts, manufactured “community” signals (e.g., forks/contributors), and placement of the malicious server into public MCP registries to increase the likelihood that developers would download it.
Once installed, the trojanized MCP server deployed StealC, which is designed to steal sensitive data including developer credentials, browser-stored passwords, and cryptocurrency wallet information. Reporting highlighted this as a tactical shift: threat actors with established software supply-chain tradecraft are now targeting the emerging MCP ecosystem used by AI tooling, increasing the risk of credential theft, data exfiltration, and downstream compromise for organizations adopting MCP-enabled AI assistants and developer workflows.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Straiker’s AI Research (STAR) Labs reported the campaign, linking the infrastructure and tradecraft to known SmartLoader patterns and noting indicators consistent with China-based operations, while warning of growing supply-chain risk in MCP ecosystems.
When downloaded and installed, the malicious MCP server deployed the StealC information stealer, using LuaJIT, VM-style obfuscation, and scheduled-task persistence disguised as Realtek drivers to steal credentials, browser passwords, wallet data, and other secrets.
After establishing trust around the cloned project, the attackers published a separate malicious repository and submitted a trojanized Oura MCP server package to public MCP registries to target developers seeking Oura integrations.
Over a period of months, attackers cloned a legitimate Oura MCP Server project and used multiple fake GitHub accounts, AI-generated personas, fake forks, and cross-referenced activity to make the project appear credible and widely adopted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.