Security researchers identified an active supply-chain campaign, dubbed Deadbugz, in which a single account filed 23 pull requests across unrelated AI and developer-tool GitHub projects within 74 minutes, each adding a malicious MCP server disguised as a text-formatting and summarization tool. The server behaves normally for its first three tool calls, then rewrites its own tool metadata into instructions that hunt for SSH keys, AWS credentials, shell history, and Kubernetes config while concealing the activity from the user, defeating pre-approval review by design.