PulseAugur
EN
LIVE 15:32:21

Hackers exploit Claude Code MCP traffic to steal OAuth tokens

A new man-in-the-middle attack has been discovered that targets Anthropic's Claude Code, allowing hackers to steal OAuth authentication tokens. The exploit leverages vulnerabilities in the Model Context Protocol (MCP) traffic and insecure local storage of tokens in the `~/.claude.json` file. This allows attackers to gain persistent, unauthorized access to enterprise SaaS platforms connected to Claude Code. AI

IMPACT This vulnerability could lead to unauthorized access to enterprise systems, highlighting the need for robust security in AI-powered developer tools.

RANK_REASON This describes a security vulnerability in a specific product's implementation, not a new model release or fundamental research.

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

COVERAGE [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Dave Kurian ·

    Hackers hijack OAuth tokens via Claude Code MCP traffic in new MitM attack

    <p>Claude Code OAuth Token Hijacking Attack: How Hackers Exploit MCP Traffic to Steal OAuth Tokens</p> <p>A new attack chain targeting Anthropic’s Claude Code ecosystem has been uncovered by Mitiga, showing how hackers exploit Model Context Protocol (MCP) traffic to hijack OAuth …