{"slug": "a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there", "title": "A fake MCP server spent three months earning trust. The tells were there", "summary": "Researchers at Straiker STAR Labs documented a supply chain operation in which a malware campaign called SmartLoader spent three months building a fake developer ecosystem around a trojanized Oura Ring MCP server before submitting it to a legitimate MCP market registry. The operation used five GitHub accounts with AI-generated personas and cross-forked repositories to simulate an active community, defeating conventional vetting signals such as commit history and star counts.", "body_md": "In February, researchers at Straiker STAR Labs documented a supply chain operation that should reset how you vet MCP servers. A malware operation known as SmartLoader spent three months constructing a fake developer ecosystem: five GitHub accounts with AI generated personas, repos cross forked to simulate an active community, all wrapped around a trojanized Oura Ring MCP server. Then it was submitted to a legitimate MCP market registry.\n\nThree months of patience. Fake commit history, fake people, fake social proof. The old advice, check the GitHub profile, check the stars, dies exactly here. Every signal on that page was farmed on purpose.\n\nWe pattern match fast. Active community, reasonable README, commits flowing in: install. The whole vetting ritual takes ninety seconds and predators know the ritual. The fake ecosystem was built to pass the ritual, not to survive scrutiny.\n\nDeep fakes of activity are cheap. Sustained, specific, boring history is expensive. These tells survived the operation and they survive the next one:\n\nBefore any MCP server goes into a config I care about:\n\nThe registry is not your threat model. Registries will tighten, add review queues, maybe attestation. Attackers will adapt, the same way they adapted to app stores. The install decision stays yours.\n\nThe browser extension ecosystem went through this exact era. We know how it went. The developers who internalized \"the marketplace listing proves nothing\" were the ones who stayed out of the incident reports.", "url": "https://wpnews.pro/news/a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there", "canonical_source": "https://dev.to/kielltampubolon/a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there-4n6l", "published_at": "2026-09-14 04:40:35+00:00", "updated_at": "2026-09-14 04:56:28.703830+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "developer-tools", "ai-tools"], "entities": ["Straiker STAR Labs", "SmartLoader", "GitHub", "Oura Ring", "MCP"], "alternates": {"html": "https://wpnews.pro/news/a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there", "markdown": "https://wpnews.pro/news/a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there.md", "text": "https://wpnews.pro/news/a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there.txt", "jsonld": "https://wpnews.pro/news/a-fake-mcp-server-spent-three-months-earning-trust-the-tells-were-there.jsonld"}}