Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Keenadu firmware backdoor infects Android tablets via signed OTA update

Here are 17 US-based AI companies that raised $100 million or more in 2026.

Ocean sensors will change how scientists track ocean carbon cycle

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » SmartLoader attack uses Trojanized Oura MCP server to deploy StealC Infostealer
Identity

SmartLoader attack uses Trojanized Oura MCP server to deploy StealC Infostealer

userBy userFebruary 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananFebruary 17, 2026Infostealer / Artificial Intelligence

Cybersecurity researchers have revealed details of a new SmartLoader campaign that involves distributing a trojanized version of the Model Context Protocol (MCP) server associated with Oura Health to provide an information theft vector known as StealC.

“Threat actors cloned the legitimate Oura MCP Server (a tool that connects AI assistants to Oura Ring health data) and created a deceptive infrastructure of fake forks and contributors to fabricate its credibility,” Striker’s AI Research (STAR) Labs team said in a report shared with The Hacker News.

The ultimate goal is to leverage a trojanized version of the Oura MCP server to deliver the StealC infostealer, allowing attackers to steal credentials, browser passwords, and data from cryptocurrency wallets.

First brought to our attention by OALABS Research in early 2024, SmartLoader is a malware loader known to be distributed via fake GitHub repositories containing artificial intelligence (AI)-generated lures to appear legitimate.

In an analysis published in March 2025, Trend Micro revealed that these repositories are disguised as game cheats, cracked software, and cryptocurrency utilities, typically promising free or unauthorized features to lure victims into downloading ZIP archives that deploy SmartLoader.

Striker’s latest findings highlight new developments in AI. Attackers create a network of fake GitHub accounts and repositories that serve Trojanized MCP servers and send them to legitimate MCP registries such as MCP Market. The MCP server is still listed in the MCP directory.

The idea is to poison MCP registries and weaponize platforms like GitHub, using the trust and reputation associated with the service to lure unsuspecting users into downloading malware.

“Unlike opportunistic malware attacks that prioritize speed and volume, SmartLoader spent months building credibility before deploying its payload,” the company said. “This patient, methodical approach shows that the attackers understand that gaining developer trust will take time, and are willing to invest that time in gaining access to high-value targets.”

The attack basically unfolded in four stages.

We created at least five fake GitHub accounts (YuzeHao2023, punkpeye, dvlan26, halamji, and yzhao112) to build a collection of seemingly legitimate repository forks of the Oura MCP server. Created another Oura MCP server repository containing a malicious payload under a new account ‘SiddhiBagul’. To feign authenticity, a newly created fake account was added as a “poster” and the original author was intentionally excluded from the list of posters. Submitted a Trojanized server to MCP Market.

This also means that when users search for the Oura MCP server on the registry, they are likely to find a rogue server that is included in a list of other safe alternative servers. When launched via a ZIP archive, it executes an obfuscated Lua script that drops the SmartLoader and begins deploying StealC.

The evolution of the SmartLoader campaign marks a shift from attacks on users looking for pirated software to developers attacking systems that tend to contain sensitive data such as API keys, cloud credentials, cryptocurrency wallets, and access to operational systems. Stolen data can be exploited to facilitate subsequent intrusions.

As a mitigation measure to combat the threat, organizations are encouraged to inventory installed MCP servers, establish formal security reviews prior to installation, verify the origin of MCP servers, and monitor suspicious outgoing traffic and persistence mechanisms.

“This campaign exposes a fundamental weakness in the way organizations evaluate AI tools,” Straker said. “SmartLoader’s success depends on security teams and developers applying outdated trust heuristics to new attack surfaces.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHow modern SOC teams use AI and context to quickly investigate cloud breaches
Next Article Ocean sensors will change how scientists track ocean carbon cycle
user
  • Website

Related Posts

Keenadu firmware backdoor infects Android tablets via signed OTA update

February 17, 2026

How modern SOC teams use AI and context to quickly investigate cloud breaches

February 17, 2026

My Day Getting My Hands Dirty with an NDR System

February 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Keenadu firmware backdoor infects Android tablets via signed OTA update

Here are 17 US-based AI companies that raised $100 million or more in 2026.

Ocean sensors will change how scientists track ocean carbon cycle

SmartLoader attack uses Trojanized Oura MCP server to deploy StealC Infostealer

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.