AIR Security researchers identified 155 Model Context Protocol (MCP) servers in the Official MCP Registry whose underlying services were offline while their associated domains had expired. An attacker can re-register one of those domains and operate a malicious server at the trusted registry address, potentially causing AI agents that retain the stale MCP configuration to connect to attacker-controlled infrastructure.
A hijacked MCP server could alter tool definitions, inject prompts, redirect agent actions, and exfiltrate data available to the agent. The exposure highlights unresolved MCP supply-chain weaknesses, including insufficient runtime endpoint verification, unsigned or unpinned server dependencies, and permissive tool execution; organizations should inventory MCP integrations, remove stale entries, verify and pin server identities, enforce least privilege and approval controls, and govern access through allowlists, internal registries, and monitoring.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
AIR Security researchers Nadav Dadush, Eliad Mualem, and Roi Snir described MCPJacking, a supply-chain attack in which expired domains behind stale official MCP Registry entries can be re-registered and used to serve attacker-controlled MCP servers. Their scan identified 155 registry entries still marked trusted despite nonfunctioning underlying services and expired domains.
Wiz researcher Gal Nagli published a proof of concept showing that an external MCP server intended to parse GitHub documentation could be exploited to achieve remote code execution on the MCP host.
Wiz announced that its MCP Server for Wiz was available in private preview.
Researcher Guy Goldenberg found injection issues affecting Anthropic's MCP PostgreSQL and Puppeteer servers.
Anthropic introduced the Model Context Protocol (MCP) to connect LLM applications with external data sources and tools.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceanthropic.com
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.