Malicious MCP Servers Can Split Exfiltration Steps
🛡️ A new technique called GhostSplice shows how a malicious Model Context Protocol (MCP) server connected to an AI coding assistant can exfiltrate SSH keys, environment secrets, source code, and customer data by splitting a theft into harmless-looking fragments. ASSET Research Group tested the approach in isolated projects using fake credentials and found that splitting the request across tool descriptions, results, or server-initiated sampling raised compliance dramatically for many models. The attack relies on developers connecting a hostile MCP server and the agent already having access to the target files.
