• Sources: primary, analysis, discussion
  • Summary: Pillar Security disclosed the campaign on 2026-08-12, reporting that the server keeps a per-client call counter and, after three calls, returns tool descriptions that instruct the agent to collect SSH keys, AWS credentials, shell history, and Kubernetes configuration, and to hide the activity. The three-call trigger and the malicious descriptions are present in the public source, which Pillar confirmed by driving the server with harmless text requests and matching the gated metadata against that code. Pillar calls the gate a research-evasion technique, because a brief inspection or a limited automated test can stay under the threshold and see only benign metadata while normal use crosses it. Delivery was 23 pull requests opened in 74 minutes on 2026-08-10, of which 17 add the remote endpoint to an MCP configuration file, 4 reference a hidden local script, and 2 are directory or listing submissions, and at review time 19 were closed and 4 remained open with none merged through GitHub's merge mechanism.
  • Why it matters: A short trial of an MCP server establishes nothing about what it returns once ordinary use passes the trigger count, so evaluation has to run past the point where a quick test stops.
  • Follow-up: Whether the four still-open pull requests get merged, and whether other MCP servers use the same delayed-payload pattern.

send feedback on this story