Research · curated 14 Jul 2026

Deleting the Malicious MCP Server Doesn't Save You | Amine Raji, PhD

Coverage timeline

16 Jun 2026aminrj.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

The MCP-to-A2A kill chain shows that removing a malicious MCP server does not evict an attacker, because the rogue A2A agent implant survives the fix and enables lateral movement and data exfiltration across an agent fleet.

A lab-built demonstration (mcp-attack-labs, Lab 08) chains MCP tool-description poisoning into an Agent-to-Agent (A2A) intrusion: a poisoned tool instructs the compromised agent to register a rogue A2A agent, hijack routing via shadowing, exfiltrate data, and persist even after the malicious MCP server is deleted. Each stage maps to a named vulnerability class (OWASP MCP Top 10 MCP03, ASI10, ASI07) and is paired with a detection that fires on it.