Programmer’s Digest #204
09/23/2026-09/30/2026 MCP Python SDK OAuth Flaw; Malware Spread Through Terraform Providers; AI-Powered CARBONATO Botnet Steals Credentials And More.
1. MCP Python SDK OAuth Flaw Lets Malicious Servers Steal Credentials and Take Over Accounts
A high-severity OAuth flaw in Anthropic’s official MCP Python SDK lets a malicious MCP server steal authentication material and take over accounts. Cycode says it affects HTTP-based clients on SDK versions 1.9.1 through 2.1.1.
The bug lies in OAuth discovery. An attacker-controlled server returns a 404 during authorization-server discovery, pushing the SDK onto a fallback path that accepts server-supplied OAuth metadata without validating the issuer. The metadata can name a legitimate provider, such as Okta, Google or Microsoft Entra ID, while pointing to an attacker’s token endpoint.
The victim still sees a real login page. Afterward, the client sends the authorization code, client secret and PKCE code_verifier to the attacker, who can redeem the code for a valid access token. Stolen secrets and refresh tokens may grant persistent access to cloud services and internal APIs.
Servers, local stdio clients and clients using their own tokens are unaffected. Upgrade to 1.30.0 or 2.2.0, clear stored registrations, and rotate secrets and revoke tokens if a client may have contacted an untrusted server. Also set issuer= explicitly for ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider.
2. The Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths
Malware has reached the tools developers use to manage cloud infrastructure. A campaign linked to Graphalgo planted a remote access program in Terraform providers and Go packages. It is the first time the firm has seen malware spread through Terraform providers.
In early September, attackers published two providers, one a typosquat of a popular Docker provider with 56 million downloads. The hidden code activates only when two Terraform inputs produce a specific hash, which makes casual testing unlikely to expose it. Two Go modules carried similar payloads, one hiding its code in an archive posing as a database file.
Once active, the malware reports system details via Slack and takes commands through Slack or an Ethereum test-network smart contract. Operators can run more Go or JavaScript code, or wipe the malware. Researchers counted 18 hostnames checking in: three Windows, five Linux and 10 Macs.
Affected teams should isolate the host, rotate credentials (cloud ones first), review recent Terraform runs and builds, and reimage. Preserve logs before cleanup.
3. Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The placeholder domain “third-party[.]com” has been serving a ClickFix lure to Windows browsers while showing a harmless decoy to other users. Unlike example.com, the domain is not IANA-reserved, so someone registered it. It is now flagged as malicious on VirusTotal and Google Safe Browsing. Since at least June 2026, Windows visitors have seen a fake Cloudflare check that poisons the clipboard and tells them to paste a command into the Run dialog, which fetches a remote PowerShell payload. macOS users see an error saying only Windows is supported. The domain appears in over 1,700 GitHub repositories, including AI agent skills and MCP-server docs.
Manifold found 13 more non-reserved placeholder domains. Two, yoursite[.]com and your-domain[.]com, serve scams and scareware to macOS users. Because the payload depends on the visitor, static file scans miss it. Developers should audit their docs and tests and use only reserved placeholders such as example.com, .org and .net.
4. AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
CARBONATO is a Docker-based botnet, active since at least October 2024, that ThreatDown uncovered after finding the attackers’ unauthenticated container registry exposed online. In one day of passive collection, researchers pulled 4.3 GB of image data covering 59 repositories, 234 tags and 605 file blobs. The image histories revealed command-and-control addresses, bot tokens and the shared password for the crew’s own AI gateway. Evidence, including UTC-06:00 timestamps, the Telegram handle “Carbo506” and Costa Rican network infrastructure, points to Costa Rica.
The bot scans for Docker daemons that accept unauthenticated connections on port 2375. It then uses the Docker API to launch a privileged container with the host filesystem mounted and runs commands on the underlying machine. The container opens a reverse SSH tunnel to a relay in Costa Rica, using a port derived from the MD5 hash of the victim’s IP, installs an SSH server with the crew’s key, and sends a deployment report to Telegram.
Afterward, the implant installs the open-source Hermes Agent, whose persona file is rewritten to prioritize stealing AI API keys, and the botnet keeps spreading across networks on its own.
5. New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse (BTR), a new Spectre v2 variant that targets Just-In-Time (JIT) engines in browsers, language runtimes and operating system kernels across multiple CPU vendors. Modern CPUs restore code coherence after self-modification but don’t necessarily invalidate stale indirect branch predictions. When a JIT engine frees code and later reuses the address, an attacker can trigger a speculative jump to the obsolete entry point, hijacking control flow and leaking data.
BTR affects SpiderMonkey (Firefox), GraalVM and the Linux kernel’s cBPF JIT. Two proof-of-concept exploits recovered the root password hash within minutes on a fully patched Intel system with default protections. The attack also undermines mitigations for Training Solo (CVE-2024-28956 and CVE-2025-24495).
Linux has merged fixes (CVE-2026-64507 and CVE-2026-64508). GraalVM now randomizes JIT code-cache locations, while Mozilla is prioritizing site isolation over IBPB-based mitigations. The researchers warn that similar CPU flaws in handling rewritten code may emerge.