Analysis
MCP Rug Pull Attacks: The Emerging Supply Chain Threat in AI Agent Ecosystems
Publication date unknown · Discovered loginsoft.com
Page published
Publication date unknown · First observed: 11 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
MCP rug-pull attacks exploit the persistent, broadly-privileged trust AI agents place in approved tools, meaning a single compromised MCP server can silently exfiltrate enterprise data without touching the model itself.
Loginsoft's write-up explains MCP rug-pull attacks, where a Model Context Protocol tool or server is reviewed and approved, then changes behavior after deployment to introduce malicious or unauthorized activity that AI agents continue to trust. The article frames this as a new AI supply-chain risk driven by trust drift, using a GitHub-assistant compromise scenario, and recommends version pinning, change detection, least privilege, and re-approval workflows.