logo

MCP Token Theft in Claude Code: A Man-in-the-Middle Attack Chain

ID: 46efa953-ea05-5bef-8ef9-0d17fd3b4c78

STIX ID: report--46efa953-ea05-5bef-8ef9-0d17fd3b4c78

Feed Name: Mitiga

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-29

...
...

This report details a technique where a malicious npm postinstall hook seeds trusted project paths and rewrites Claude Code’s MCP configuration (~/.claude.json) to point at an attacker-controlled proxy, enabling interception and long-lived theft of OAuth bearer/refresh tokens for SaaS like Jira/Confluence; the hook persists by reseeding on each load so token rotation alone is insufficient, and defenders are advised to monitor MCP endpoints, config changes, local proxies, and unusual SaaS activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.