Fetching from the wire…
Public story · 2026-02-26 · source-backed
The SANDWORM_MODE npm worm introduces a brand-new attack class: malicious MCP server injection via supply chain compromise. At least 19 typosquatted packages modify MCP configurations of Claude Code, Cursor, Windsurf, and VS Code Continue, installing rogue MCP servers that harvest credentials. The dormant dead switch adds a wiper capability. Builder opportunity: MCP security scanning tools (runtime monitoring, config integrity checking, tool manifest verification) are wide open as a product category.
Each link below shares sources, entities, or timing with this story.
A multi-stage npm supply chain worm dubbed SANDWORM_MODE deploys rogue MCP servers into configurations of Claude Code, Claude Desktop, Cursor, VS Code Continue, and Windsurf. At least 19 typosquatted packages harvest npm/GitHub tokens, SSH keys, and cloud credentials, then pro...
Socket.dev disclosed a self-replicating npm worm with a McpInject module that creates fake MCP servers targeting Claude Code, Cursor, Windsurf, VS Code Continue, and Claude Desktop. At least 19 typosquatted packages were compromised. This is purpose-built malware targeting the...
The Amazon Q bug is one instance of a 2026 pattern: MCP configuration carried in repositories is now an RCE supply-chain vector, not just untrusted tool output. Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI are all vulnerable to MCP-based auto-launch attacks (Windsurf...
The June 12 release connects Cursor, Claude Code, Windsurf, VS Code, Amazon Q, and Kiro to pipeline, build, log, test, and workflow data over MCP. Agents can reason over CI state, like diagnosing a failing build straight from logs, without copy-paste. MCP is becoming the defau...
MIT-licensed desktop app and CLI that auto-detects installed AI clients and manages MCP server configuration for all of them — Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, ChatGPT Desktop, Gemini CLI. Built-in MCP marketplace, team snapshot export, automatic backups...
lean-ctx is a Rust-based system that sits between AI coding tools and LLMs, compressing file reads by 60-99% and shell output by 60-95% using Tree-sitter AST parsing for 18 languages. Cached re-reads cost only 13 tokens. Works as a standard MCP server with 49 tools. Compatible...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.