Securityaffairs.Co
SmartLoader Campaign Uses Fake Oura MCP Server to Distribute StealC Malware
First seen 17 Feb 2026, 20:11 UTC
•
•36.9
Export
Article Content
Browse articles
Hackers exploited a cloned Oura MCP server to distribute the StealC info-stealer malware. The attack was uncovered by Straiker’s AI Research (STAR) Labs, revealing that the fake project was designed to appear legitimate, complete with counterfeit forks to deceive users into downloading the malware.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-17
SmartLoader campaign discovered by STAR Labs
2026-02-17
Fake Oura MCP server identified as malware distribution method
More articles in this cluster
Continue Reading
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack
VoidStealer and Infostealers Bypass Chrome's App-Bound Encryption
Fake CAPTCHA Scams Evolve into Malware Delivery Systems
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique