Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Claude Code to Steal OAuth Tokens

Hackers Exploit Claude Code to Steal OAuth Tokens

Posted on June 8, 2026 By CWS

Security researchers have discovered a sophisticated method for intercepting OAuth tokens through Claude Code’s Model Context Protocol (MCP). The attack involves redirecting MCP traffic via a malicious npm package, giving attackers persistent access to SaaS platforms like Jira and GitHub. Despite the severity, no patch has been announced by Anthropic.

Understanding the Attack Mechanism

Researchers from Mitiga Labs demonstrated the attack, which begins with a deceptive npm package. This package includes a postinstall hook that executes silently, a common tactic in supply chain attacks, but with new implications in AI environments. The hook targets the ~/.claude.json file, managing Claude Code’s MCP traffic and storing OAuth tokens in plaintext.

After installation, the hook sets trust flags across common developer directories, avoiding prompts for user approval. When a developer connects an MCP server, such as GitHub, the program completes the OAuth process, unwittingly handing over tokens to the attacker.

Exploiting OAuth Tokens

The captured OAuth tokens have characteristics that make them valuable to attackers. They are persistent, allowing reuse with a refresh token, and broadly scoped, inheriting all permissions granted during authorization. Stored in plaintext, they are vulnerable to theft, while their use from Anthropic’s IP range makes them indistinguishable from legitimate traffic.

The attack chain involves several steps, starting with the malicious npm package installation, which seeds trust flags and alters the ~/.claude.json file. This alteration redirects MCP endpoints to an attacker-controlled proxy, capturing tokens during the OAuth process. The configuration is persistently reseeded, maintaining the attack even after token rotation.

Defense and Mitigation Strategies

Security teams face challenges in detecting this attack, as standard response actions, like token rotation, inadvertently assist attackers. To combat this, teams should monitor ~/.claude.json for unauthorized changes and audit npm packages for risky scripts. Tokens should be rotated only after confirming the removal of malicious hooks.

Mitiga Labs reported the findings to Anthropic, who acknowledged the issue but deemed it out of scope, placing the onus of detection on security teams. Therefore, proactive monitoring of SaaS audit logs and unexpected local proxy behavior is crucial. Security teams should verify the legitimacy of MCP server URLs in their Claude Code configurations immediately.

For ongoing protection, organizations are urged to treat npm post-install hooks as significant supply chain risks and to regularly audit and rotate OAuth tokens connected to Claude Code integrations. This vigilance is key to preventing unauthorized access and safeguarding sensitive data.

Cyber Security News Tags:AI security, Anthropic, Claude Code, Claude Code MCP, Cybersecurity, Mitiga Labs, npm packages, OAuth tokens, SaaS security, supply chain attack

Post navigation

Previous Post: New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
Next Post: Microsoft Highlights Security Risks in Claude Code GitHub Action

Related Posts

Critical Vulnerabilities in Citrix Clients Pose Security Risks Critical Vulnerabilities in Citrix Clients Pose Security Risks Cyber Security News
Vulnerability in GCP Dialogflow Enables Malicious Code Injection Vulnerability in GCP Dialogflow Enables Malicious Code Injection Cyber Security News
Google Chrome Update: Fixes 29 Security Vulnerabilities Google Chrome Update: Fixes 29 Security Vulnerabilities Cyber Security News
UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS Cyber Security News
Anthropic’s MCP Server Vulnerability Let Attackers Escape Server’s Sandbox and Execute Arbitrary Code Anthropic’s MCP Server Vulnerability Let Attackers Escape Server’s Sandbox and Execute Arbitrary Code Cyber Security News
Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark