Skip to content
SmartLoader Campaign Uses Fake Oura MCP Server to Distribute StealC Malware

SmartLoader Campaign Uses Fake Oura MCP Server to Distribute StealC Malware

First seen 17 Feb 2026, 20:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Hackers exploited a cloned Oura MCP server to distribute the StealC info-stealer malware. The attack was uncovered by Straiker’s AI Research (STAR) Labs, revealing that the fake project was designed to appear legitimate, complete with counterfeit forks to deceive users into downloading the malware.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 211d ago How this analysis works

Timeline

2026-02-17
SmartLoader campaign discovered by STAR Labs
2026-02-17
Fake Oura MCP server identified as malware distribution method

More articles in this cluster (2)

Following this threat?

Track StealC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed