Switch language한국어
Back to the list

MCP marketplaces shipped LOLBAS malware. We audited 256 agents.

TL;DR AI

Key summary

2 min read
  1. A security audit found that a public MCP marketplace shipped an agent using a LOLBAS chain to fetch and run remote payloads via a signed Microsoft binary.

  2. Because the payload stayed hidden inside trusted system binaries, normal static scans could miss it, creating a supply-chain and endpoint-security risk.

  3. Researchers audited 256 agents with 27 checks and positioned Trust Agent as a vetted alternative.

  4. The case highlights how AI agent marketplaces can become a delivery channel for malware-like behavior and signed binary proxy execution.

  5. It maps closely to MITRE ATT&CK T1218 and raises the bar for marketplace security and agent vetting.

Read the original