BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Oura Health MCP Server Delivers StealC Infostealer

Fake Oura MCP server on public registry deploys StealC infostealer via trojanized AI tooling.

  • Threat actors distributed a trojanized Oura Ring health data server to deploy the StealC information stealer.
  • The sophisticated campaign used fake GitHub accounts and forked repositories to build false credibility over months.
  • Attackers targeted developers’ systems, which are high-value for sensitive data like API keys and cryptocurrency wallets.
  • The malicious MCP server was submitted to a legitimate public registry where it remains listed.
  • Organizations are advised to formally review and verify the origin of AI tooling before installation.

Cybersecurity researchers revealed a new SmartLoader campaign on Feb 17, 2026, which uses a weaponized version of an Oura Ring health data server to steal cryptocurrency wallets and credentials. The attackers cloned a legitimate Oura Model Context Protocol (MCP) server to build deceptive infrastructure and manufacture credibility, according to a report from Straiker’s AI Research (STAR) Labs.

- Advertisement -

SmartLoader is a malware loader first highlighted in early 2024, known for distribution via fake GitHub repositories containing AI-generated lures. This method previously disguised repositories as game cheats, cracked software, and cryptocurrency utilities to coax victims.

However, the latest findings highlight a new AI twist involving bogus GitHub accounts and repositories. Consequently, the threat actors submitted the trojanized server to legitimate MCP registries like MCP Market, where it is still listed.

This patient approach invested months in building credibility before deploying the final payload. The attack unfolded over four distinct stages to create a convincing facade.

Firstly, the actors created at least five fake GitHub accounts to build a collection of seemingly legitimate repository forks. They then created another Oura MCP server repository containing the malicious payload under a new account.

- Advertisement -

Next, they added the fake accounts as “contributors” to lend credibility while excluding the original author. Finally, they submitted the trojanized server to the public MCP Market directory for discovery.

Once executed, an obfuscated Lua script drops SmartLoader, which then deploys the StealC infostealer. This evolution marks a significant shift from targeting users of pirated software to directly attacking developers.

Developers’ systems are high-value targets because they often contain sensitive data like API keys and cloud credentials. Consequently, the stolen information could be abused to fuel follow-on intrusions.

As a mitigation, organizations should inventory installed MCP servers and establish a formal security review. Straiker stated, “This campaign exposes fundamental weaknesses in how organizations evaluate AI tooling.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Webinar: Secure Hidden AI and API Keys

Compromised service accounts and API keys caused 68% of cloud breaches in 2024, a...

Bitcoin Eyes $82K by April’s End Amid Volatility

Analysts predict a final push for Bitcoin towards the $78,000-$80,000 zone before a potential...

Worldcoin Drops 13% Despite Zoom, Docusign ID Deals

Worldcoin (WLD) dropped 13.4% to roughly $0.28 on Friday, contrasting with a broader crypto...

Bitcoin Soars Past Key Resistance; Traders See 69% Chance of $84K

Bitcoin surged 2.7%, breaking a key descending resistance line that had suppressed its price...

$650M In Shorts Liquidated Amid Bitcoin Surge

Over $800 million in crypto positions were liquidated in 24 hours as Bitcoin surged...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading