cd /news/ai-safety/a-fake-mcp-server-spent-three-months… · home topics ai-safety article
[ARTICLE · art-128742] src=dev.to ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

A fake MCP server spent three months earning trust. The tells were there

Researchers at Straiker STAR Labs documented a supply chain operation in which a malware campaign called SmartLoader spent three months building a fake developer ecosystem around a trojanized Oura Ring MCP server before submitting it to a legitimate MCP market registry. The operation used five GitHub accounts with AI-generated personas and cross-forked repositories to simulate an active community, defeating conventional vetting signals such as commit history and star counts.

by read1 min views1 publishedSep 14, 2026

In February, researchers at Straiker STAR Labs documented a supply chain operation that should reset how you vet MCP servers. A malware operation known as Smart spent three months constructing a fake developer ecosystem: five GitHub accounts with AI generated personas, repos cross forked to simulate an active community, all wrapped around a trojanized Oura Ring MCP server. Then it was submitted to a legitimate MCP market registry.

Three months of patience. Fake commit history, fake people, fake social proof. The old advice, check the GitHub profile, check the stars, dies exactly here. Every signal on that page was farmed on purpose.

We pattern match fast. Active community, reasonable README, commits flowing in: install. The whole vetting ritual takes ninety seconds and predators know the ritual. The fake ecosystem was built to pass the ritual, not to survive scrutiny.

Deep fakes of activity are cheap. Sustained, specific, boring history is expensive. These tells survived the operation and they survive the next one:

Before any MCP server goes into a config I care about:

The registry is not your threat model. Registries will tighten, add review queues, maybe attestation. Attackers will adapt, the same way they adapted to app stores. The install decision stays yours.

The browser extension ecosystem went through this exact era. We know how it went. The developers who internalized "the marketplace listing proves nothing" were the ones who stayed out of the incident reports.

── more in #ai-safety 4 stories · sorted by recency
── more on @straiker star labs 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-fake-mcp-server-sp…] indexed:0 read:1min 2026-09-14 ·