Research · curated 4 Oct 2026

Rug Pulls and Silent Redefinition - HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community

Coverage timeline

4 Oct 2026hacklido.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

MCP rug pulls defeat one-time security review because the tool definition an agent runs in production can silently differ from the one a defender audited, making runtime tool descriptions a live supply-chain attack surface.

A HACKLIDO blog entry explains the mechanics of MCP 'rug pull' attacks, where a tool server serves clean, auditable tool descriptions at install time and later swaps in poisoned ones at runtime via tools/list fetches. It references the real postmark-mcp case—the first confirmed malicious MCP server caught in the wild, which shipped fifteen clean versions before adding exfiltration code—and walks through scheduled, targeted, and conditional pull variants with lab PoC code.