CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

SmartLoader Campaign Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new SmartLoader campaign involves distributing a trojanized version of the Oura Model Context Protocol (MCP) server to deliver the StealC infostealer. The attackers cloned the legitimate Oura MCP Server, created fake GitHub repositories and contributors to build credibility, and submitted the trojanized server to MCP registries. The campaign targets developers, stealing credentials, browser passwords, and cryptocurrency wallet data. The attack unfolded over four stages, involving the creation of fake GitHub accounts, repositories, and contributors, followed by submission to MCP Market. The trojanized server executes an obfuscated Lua script that drops SmartLoader, which then deploys StealC. The evolution of SmartLoader indicates a shift towards targeting developers, whose systems contain sensitive data like API keys and cloud credentials.

Timeline

  1. 17.02.2026 14:42 1 articles · 10h ago

    SmartLoader Campaign Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

    A new SmartLoader campaign involves distributing a trojanized version of the Oura Model Context Protocol (MCP) server to deliver the StealC infostealer. The attackers cloned the legitimate Oura MCP Server, created fake GitHub repositories and contributors to build credibility, and submitted the trojanized server to MCP registries. The campaign targets developers, stealing credentials, browser passwords, and cryptocurrency wallet data. The attack unfolded over four stages, involving the creation of fake GitHub accounts, repositories, and contributors, followed by submission to MCP Market. The trojanized server executes an obfuscated Lua script that drops SmartLoader, which then deploys StealC. The evolution of SmartLoader indicates a shift towards targeting developers, whose systems contain sensitive data like API keys and cloud credentials.

    Show sources

Information Snippets