Pillar Security has described Deadbugz, a campaign in which one GitHub account submitted 23 pull requests in 74 minutes on 10 August 2026, each adding an MCP server that behaves normally at first and later instructs the connected AI agent to look for credentials [1]. MCP, the Model Context Protocol, is the standard many AI agents use to call outside tools.
Background
An MCP server tells an agent which tools it offers and what they do, and the agent reads those descriptions as instructions. A server that changes its descriptions after installation can therefore change what the agent does without changing the code a reviewer saw [1].
What the report describes
The pull requests came from a public account named zellkernel and went to unrelated AI and developer-tool projects between 9:52 PM and 11:07 PM UTC. Seventeen configured a remote MCP endpoint, four referenced a hidden local Python script and two were directory submissions. Nineteen were closed and four were still open when Pillar reviewed them, and none had been merged through GitHub's merge mechanism [1].
The server, called productivity-suite, offers text formatting and summarising. After a connected client makes three tool calls, it rewrites its own tool descriptions so that the agent is told to look for SSH keys, AWS credentials, shell history and Kubernetes configuration while hiding the activity from the user. Pillar says the remote endpoint was still active at the time of its analysis [1].
Implications for Mac users
Developers who add MCP servers to an agent's configuration, or who accept pull requests that do, are the exposed group. Pillar reports no merge, so the campaign as described had not succeeded through GitHub at the time of review. A developer who copied one of the configurations by hand would fall outside that count [1].
Recommendations
- Review any pull request that adds or changes an MCP server entry as carefully as one that adds code.
- Search machines and repositories for the endpoint and script path Pillar lists, and revert changes that introduce them.
- Prefer MCP clients that warn when a server changes its tool definitions after approval, which Pillar recommends.
- Keep SSH keys, cloud credentials and shell history out of reach of agent processes where possible.
Relevance to FireAI
FireAI does not read MCP configurations or the instructions an agent receives, and it cannot tell an agent to ignore them. For a remote server such as the one described, each connection is a network event: a first connection from an app to a new destination triggers a prompt in Alert mode, and a per-app rule can block that host. A server that runs locally and only reads files generates no network traffic for FireAI to see.
Limitations
The fetched text of the report does not show a publication date. Attribution rests on the public account, and the operator behind it is unknown. The report does not say whether any agent actually ran the hostile instructions or whether any credentials were taken [1].
Try FireAI, by HisnLabs free for 17 days.