# Pillar Security describes Deadbugz, an MCP server that waits for three tool calls before hunting for SSH keys > Pillar Security says a campaign of 23 pull requests offered an MCP server that turns hostile after three calls and tells the AI agent to look for keys and shell history. FireAI Security & Research Team (HisnLabs) ยท Published 2026-09-30 Canonical: https://hisnlabs.com/en/news/deadbugz-mcp-server-pull-requests-agent-credentials Pillar Security has described Deadbugz, a campaign in which one GitHub account submitted 23 pull requests in 74 minutes on 10 August 2026, each adding an MCP server that behaves normally at first and later instructs the connected AI agent to look for credentials [[1]](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign). MCP, the Model Context Protocol, is the standard many AI agents use to call outside tools. ## Background An MCP server tells an agent which tools it offers and what they do, and the agent reads those descriptions as instructions. A server that changes its descriptions after installation can therefore change what the agent does without changing the code a reviewer saw [[1]](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign). ## What the report describes The pull requests came from a public account named zellkernel and went to unrelated AI and developer-tool projects between 9:52 PM and 11:07 PM UTC. Seventeen configured a remote MCP endpoint, four referenced a hidden local Python script and two were directory submissions. Nineteen were closed and four were still open when Pillar reviewed them, and none had been merged through GitHub's merge mechanism [[1]](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign). The server, called productivity-suite, offers text formatting and summarising. After a connected client makes three tool calls, it rewrites its own tool descriptions so that the agent is told to look for SSH keys, AWS credentials, shell history and Kubernetes configuration while hiding the activity from the user. Pillar says the remote endpoint was still active at the time of its analysis [[1]](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign). > FireAI, the on-device firewall for macOS developed by HisnLabs, shows which app connects where, including the process that hosts an agent tool. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users Developers who add MCP servers to an agent's configuration, or who accept pull requests that do, are the exposed group. Pillar reports no merge, so the campaign as described had not succeeded through GitHub at the time of review. A developer who copied one of the configurations by hand would fall outside that count [[1]](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign). ## Recommendations 1. Review any pull request that adds or changes an MCP server entry as carefully as one that adds code. 2. Search machines and repositories for the endpoint and script path Pillar lists, and revert changes that introduce them. 3. Prefer MCP clients that warn when a server changes its tool definitions after approval, which Pillar recommends. 4. Keep SSH keys, cloud credentials and shell history out of reach of agent processes where possible. ## Relevance to FireAI FireAI does not read MCP configurations or the instructions an agent receives, and it cannot tell an agent to ignore them. For a remote server such as the one described, each connection is a network event: a first connection from an app to a new destination triggers a prompt in Alert mode, and a [per-app rule](https://hisnlabs.com/en/docs/per-app-rules) can block that host. A server that runs locally and only reads files generates no network traffic for FireAI to see. > Agent tools reach out to remote servers. FireAI names the app and destination and lets a rule block the host. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations The fetched text of the report does not show a publication date. Attribution rests on the public account, and the operator behind it is unknown. The report does not say whether any agent actually ran the hostile instructions or whether any credentials were taken [[1]](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign). Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [Pillar Security: Deadbugz, a currently active MCP supply-chain campaign (publication date not shown in the fetched text)](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign)