Threat · curated 16 Jul 2026
MCP Token Theft in Claude Code: A Man-in-the-Middle Attack Chain
First reported mitiga.io
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
MCP token theft via ~/.claude.json lets an attacker impersonate a trusted AI-agent session against downstream SaaS with no obvious alert, giving defenders a new configuration-tampering pivot they must monitor.
Mitiga Labs research details a man-in-the-middle attack chain against Claude Code in which a user-level post-install hook rewrites MCP server endpoints in ~/.claude.json to route MCP traffic through attacker-controlled infrastructure and steal OAuth tokens for connected SaaS (Jira, Confluence, GitHub, etc.). Because provider-side audit logs still show valid OAuth traffic from Anthropic's trusted egress range, the malicious activity blends in as legitimate user actions, and token rotation fails to break the chain while the hook keeps reseeding the config.