The tooling itself was the attack surface.

Published Jul 30, 2026 · full chronicle
3
named incidents
covered below
12
CVEs at CVSS ≥ 7 filed
against agent tooling
128
tracked events since Apr 2025
incidents + CVEs, cumulative

Mastra npm scope backdoored via a dormant contributor account

A former contributor’s npm account, its scope access never revoked, shipped trojanized builds of roughly 145 packages of the Mastra agent framework. Microsoft attributed the campaign to North Korea’s Sapphire Sleet; the postinstall payload read browser data, targeted 160+ wallet extensions and allowed remote command execution.

Sources: The Hacker News · Microsoft

4,982 security issues across public MCP servers

Trend Micro scanned 9,695 MCP servers across four public directories: 2,259 had confirmed issues, including 880 arbitrary file access and 476 command injection flaws. Popularity, verification badges and repository activity barely correlated with actual security.

Sources: Trend Micro

Claude Code GitHub Action steered into leaking CI secrets

Microsoft researchers showed that prompt injection hidden in issues, pull requests or comments could drive the Action to read and exfiltrate pipeline credentials, hiding the shell payload behind a response from an attacker-controlled domain. Reported in April, fixed in Claude Code 2.1.128 in May, detailed publicly in June.

Sources: Decrypt · CSA Labs

None of this required tricking a human. The packages an agent installs, the servers it talks to, the pipeline it runs in: every layer an agent trusts was probed this month, and at every layer the loot was the same, standing credentials.

Get the next report
One email when the next issue ships, plus early access to SafeClaw. Nothing in between.