{"success":true,"data":{"id":"mcp-server-config-install-lure","label":"MCP config install lure — email asks you to paste hostile JSON into ~/.cursor/mcp.json / claude_desktop_config (2026 AI-tool supply chain attack)","description":"Email lures the recipient into pasting hostile JSON configuration into a local AI-coding-tool Model Context Protocol (MCP) config file (~/.cursor/mcp.json, claude_desktop_config.json, ~/.continue/config.json, ~/.cline/config, Windsurf / Codeium config paths). Once the config is saved and the tool restarts, the attacker has a local subprocess running with the user's privileges and can read conversation context, exfiltrate environment tokens, and execute arbitrary shell commands. Fires when the body references MCP configuration (mcpServers / model-context-protocol / mcp.json) AND either a well-known config path or a JSON block with the MCP shape (command+args for stdio transport, or url+sse for remote transport), from a sender that is NOT a known AI-tool vendor (Anthropic, Cursor, Continue, Sourcegraph, Codeium, Windsurf, Cline, ModelContextProtocol.io, OpenAI). Replies (In-Reply-To present) and newsletters (List-Unsubscribe present) are exempted because colleague config-sharing and developer-newsletter articles are legitimate contexts.","tier":"danger","category":"other","isThin":false}}