MCP Token Theft in Claude Code: A Man-in-the-Middle Attack Chain
ID: 46efa953-ea05-5bef-8ef9-0d17fd3b4c78
STIX ID: report--46efa953-ea05-5bef-8ef9-0d17fd3b4c78
Feed Name: Mitiga
This report details a technique where a malicious npm postinstall hook seeds trusted project paths and rewrites Claude Code’s MCP configuration (~/.claude.json) to point at an attacker-controlled proxy, enabling interception and long-lived theft of OAuth bearer/refresh tokens for SaaS like Jira/Confluence; the hook persists by reseeding on each load so token rotation alone is insufficient, and defenders are advised to monitor MCP endpoints, config changes, local proxies, and unusual SaaS activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
