Editorial

MCP servers that AI agents install are a different risk class

RobertUpdated Sep 25, 20264 min readmethodology
Terminal-style graphic: agent MCP install with low downloads and Attestd supply_chain.compromised true

AI agents do not install dependencies the way humans do. A human hesitates at an unfamiliar MCP server name with eleven weekly downloads. An agent follows a README, a tool catalogue, or its own prior suggestion, then runs npm install with whatever privileges the IDE session already holds.

That gap is now a concrete package class, not a hypothetical.

What happened#

On 7 September 2026, Aikido reported that the Shai-Hulud worm payload from the May @antv wave resurfaced after 111 days of silence. Among the four packages published the same hour was [email protected], carrying the same SHA-256 hash Aikido and other vendors had already fingerprinted in May (Aikido write-up). That is a public advisory naming the package and version. It is not a guess from the package name alone.

Earlier in 2026, ThreatClaw documented an OSV malware cluster (MAL-2026-5399 through MAL-2026-5403) that included MCP-shaped names such as t-invest-mcp-server and screenpipe-mcp-http (ThreatClaw discussion). Treat that as a class signal: attackers are publishing into the MCP naming surface because agents and developers are searching there.

Separately, npm's public download API reported 7 downloads for feishu-docx-mcp in the week of 15 to 21 September 2026 (verified 23 September 2026). The registry listing is now a security holding package. Low download counts are a fact about telemetry. They are also exactly what a popularity-threshold scanner is trained to ignore.

What privilege an MCP install buys#

An MCP server is not a leaf utility library. Once connected, it typically can authenticate to the agent host, expose tools the model may invoke, and reach local files, APIs, or credentials the session already has. Attestd's own MCP integration docs describe that install path from the defender side: agents should be able to ask a dependency gate before a package becomes a running tool process.

The risk shape is therefore inverted relative to mass CVE programmes:

  • High privilege once installed (tools, env, IDE hooks).
  • Often low download volume because each team installs a handful of servers, not a shared runtime used by millions of apps.
  • Name-driven discovery (*-mcp, *-mcp-server) that typosquats and hallucination-adjacent names can exploit.

Popularity thresholds optimised for "is this in enough lockfiles to justify SCA coverage?" systematically under-weight that class until an OSV MAL entry lands after the fact.

What Attestd returns for a named advisory version#

For the Aikido-named version, a live Attestd GET /v1/check on 23 September 2026 returned:

text
product: feishu-docx-mcp
version: 0.3.2
risk_state: critical
cve_ids: []
risk_factors: ["supply_chain_compromised"]
supply_chain.compromised: true
supply_chain.sources: ["osv"]
supply_chain.compromised_at: 2026-09-07T13:51:36Z

Empty CVE lists with supply_chain.compromised: true is the same independent-condition model as compromise vs CVE. A download-threshold policy would have skipped a package with single-digit weekly downloads. The compromise field would not.

bash
curl "https://api.attestd.io/v1/check?product=feishu-docx-mcp&version=0.3.2&ecosystem=npm" \
  -H "Authorization: Bearer $ATTESTD_API_KEY"

Use that as a pre-install branch for agent and IDE workflows, not as a substitute for reading the advisory. Wire it where agents actually decide, as in the AI agents use case and thesis: the check has to win the race against npm install.

What to do before an agent adds an MCP server#

Require an explicit allowlist for MCP package names in agent and IDE configs. Prefer pinned versions over floating tags. Run a compromise and typosquat check on the exact name and version before install, including packages that look "too small to matter." Treat MCP-named typosquats from public MAL clusters as evidence that the naming surface is already hunted. After any confirmed malicious MCP package ran in a workstation session, rotate tokens and review IDE persistence files the worm families favour (Aikido notes .vscode/tasks.json and .claude/settings.json for the resurfaced payload).

Related reading on adjacent npm worm and agent surfaces: Shai-Hulud wave 3 and Attestd's hosted MCP server launch.

Low downloads are not a safety filter for agents#

Agent-installed MCP servers combine high privilege with low popularity. Download-threshold watchlists miss that class until post-facto OSV ingestion. When a public advisory names a version, gate on supply_chain.compromised before the agent turns the package into a tool. Popularity never answered the install question for this surface. Privilege did.