OWASP has published a beta Top 10 for Model Context Protocol (MCP), warning that MCP-enabled AI systems introduce new attack surfaces across token handling, privilege management, tool integrity, supply chain security, command execution, authentication, telemetry, shadow deployments, and context sharing. The project frames MCP as a fast-growing integration layer for AI tools and agents, and highlights the need for stronger controls as organizations connect models to external tools, data sources, and developer workflows.
Security researchers and vendors are also warning that AI is expanding software supply chain risk through package hallucinations and slopsquatting, in which attackers register malicious packages under names invented by coding assistants. One cited proof of concept involved the hallucinated package huggingface-cli, which was later downloaded more than 30,000 times after publication as a benign placeholder. Researchers say autonomous coding agents can amplify the danger by installing dependencies with little or no human review, while related risks include malicious package campaigns, secret leakage in AI-generated code, and broader compromise of developer environments and software delivery pipelines.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A 2023 proof of concept used the hallucinated package name 'huggingface-cli,' which was published as a benign placeholder and later downloaded more than 30,000 times. The example demonstrated how hallucinated dependency names could be claimed in public registries.
Xygeni published an analysis describing AI as a meaningful software supply chain attack surface, highlighting slopsquatting, autonomous agent-driven dependency risk, malicious package campaigns, MCP exposure, and secret leakage through AI-generated code.
OWASP published its MCP Top 10 project page describing a 2025 list of ten security risk categories for Model Context Protocol-enabled AI systems. The page states the project is in Phase 3 beta release and pilot testing.
Lasso Research published findings on AI package hallucinations, documenting the risk that AI systems may invent package names that can then be abused in software supply chains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.