•11 min read•Security & Governance
MCP Supply Chain Poisoning: How Rogue Servers and Hallucinated Packages Compromise AI Toolchains
In February 2026, a worm-like npm campaign injected rogue MCP servers into Claude Code, Cursor, and Windsurf. Two months later, OX Security disclosed 200,000 vulnerable MCP instances. Then came slopsquatting. Here is how the AI coding supply chain is being weaponized.