Detecting the Confused Deputy in Azure DevOps MCP
A hidden pull-request comment turned legitimate MCP calls into a cross-project data path. Detecting it requires source, identity, scope, sequence, and sink.
reading series / 7 notes
Read these in order, or jump directly to the problem you are working on.
A hidden pull-request comment turned legitimate MCP calls into a cross-project data path. Detecting it requires source, identity, scope, sequence, and sink.
Five models produced the same 127 package-name candidates. Registry review narrowed them to 53 registrable slopsquatting targets, turning model hallucinations into a supply-chain watchlist.
CrowdStrike found viable detection signals for nine of fourteen SANDWORM_MODE behaviors, but only two were reliable enough to alert. The result shows where behavioral detection weakens and where provenance still helps.
Hugging Face reconstructed roughly 17,600 actions across an autonomous intrusion. The durable lesson is a detection contract that joins agent, identity, Kubernetes, network, and source-control evidence.
An OpenAI model evaluation became a real intrusion into Hugging Face. The useful lessons are about containment, credentials, ephemeral telemetry, and whether responders can analyze hostile evidence.
ChainDrop used npm lifecycle scripts to steal credentials and spread, then planted Claude Code and VS Code configuration as secondary execution paths. Those files belong in the executable supply-chain surface.
GhostJacking shows how attacker-controlled text can cross from WAF events, logs, and error reports into privileged agent actions. The missing control is provenance from evidence to side effect.