MCP: The AI Protocol Quietly Expanding Your Attack Surface | UpGuard
ID: 6c0dc750-bf45-5000-b077-c4bfc72bf1e7
STIX ID: report--6c0dc750-bf45-5000-b077-c4bfc72bf1e7
Feed Name: UpGuard Blog
In February 2026 researchers uncovered SmartLoader — a malware operation that has shifted from targeting consumers to developers by abusing the Model Context Protocol (MCP). MCP, a standardized connection layer adopted widely by developer AI tools, allows unvetted external servers to request and act on data with developer privileges; SmartLoader leverages this to exfiltrate browser passwords, cloud tokens, and SSH keys. The report outlines MCP's host/server/client architecture, the large population of unverified MCP servers across public registries, the heightened risk compared to traditional Shadow IT, and provides four pragmatic discovery questions for security teams to quickly assess exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
