The tooling itself was the attack surface.
covered below
against agent tooling
incidents + CVEs, cumulative
Mastra npm scope backdoored via a dormant contributor account
A former contributor’s npm account, its scope access never revoked, shipped trojanized builds of roughly 145 packages of the Mastra agent framework. Microsoft attributed the campaign to North Korea’s Sapphire Sleet; the postinstall payload read browser data, targeted 160+ wallet extensions and allowed remote command execution.
4,982 security issues across public MCP servers
Trend Micro scanned 9,695 MCP servers across four public directories: 2,259 had confirmed issues, including 880 arbitrary file access and 476 command injection flaws. Popularity, verification badges and repository activity barely correlated with actual security.
Claude Code GitHub Action steered into leaking CI secrets
Microsoft researchers showed that prompt injection hidden in issues, pull requests or comments could drive the Action to read and exfiltrate pipeline credentials, hiding the shell payload behind a response from an attacker-controlled domain. Reported in April, fixed in Claude Code 2.1.128 in May, detailed publicly in June.
None of this required tricking a human. The packages an agent installs, the servers it talks to, the pipeline it runs in: every layer an agent trusts was probed this month, and at every layer the loot was the same, standing credentials.