# Claude Code OAuth Tokens Exposed: Critical MCP Hijacking Vulnerability Reveals Supply Chain Risk in AI Development Tools


Researchers at Mitiga have discovered a critical vulnerability that allows attackers to silently intercept OAuth tokens from Claude Code users by hijacking Model Context Protocol (MCP) traffic. The attack enables persistent access to connected SaaS platforms and represents a significant supply chain security gap in the growing ecosystem of AI-assisted development tools.


## The Threat


Claude Code, Anthropic's integrated development environment for AI-assisted software engineering, integrates with multiple cloud services and APIs through MCP—a protocol that enables Claude to interact with external systems. Mitiga's research reveals that attackers can intercept OAuth tokens transmitted through this protocol channel, potentially gaining unauthorized access to a developer's connected services without triggering security alerts.


The vulnerability is particularly concerning because:


  • Silent interception: The attack leaves minimal forensic traces
  • Persistent access: Compromised tokens grant long-lived access to SaaS platforms
  • Supply chain implications: Attackers could potentially maintain access to development pipelines and repositories
  • Widespread exposure: Any Claude Code user with MCP integrations is potentially vulnerable
  • Cascading compromise: A single compromised token could expose multiple connected services (GitHub, AWS, Google Cloud, etc.)

  • ## Background and Context


    ### What Is Model Context Protocol?


    Model Context Protocol is a standardized interface that allows AI assistants to safely interact with external systems, databases, and APIs. Rather than embedding service-specific logic directly into Claude, MCP acts as a middleware layer that manages these connections.


    For Claude Code users, MCP enables features like:

  • Integration with version control systems (GitHub, GitLab)
  • Access to cloud platforms (AWS, Google Cloud, Azure)
  • Database queries and management
  • CI/CD pipeline interactions
  • API endpoint testing and development

  • ### The MCP Architecture Gap


    While MCP was designed with security in mind, the research identifies a critical assumption: that the communication channel between Claude Code and MCP servers is inherently trusted. This assumption breaks down when attackers can position themselves between the client and the MCP endpoint.


    The vulnerability stems from insufficient validation of:

  • MCP server identity during connection establishment
  • Encryption of token transmission within the protocol
  • Monitoring of token usage patterns for anomalies

  • ## Technical Details


    ### How the Attack Works


    Step 1: Traffic Interception


    Attackers can intercept MCP traffic through multiple vectors:

  • Network-level attacks (ARP spoofing, DNS hijacking on shared networks)
  • Compromised proxy servers or VPNs
  • Malicious browser extensions (if Claude Code runs in browser context)
  • Compromised local network infrastructure

  • Step 2: Token Extraction


    Once traffic is intercepted, attackers can:

  • Extract OAuth tokens from MCP authentication requests
  • Capture API keys transmitted through the protocol
  • Intercept refresh tokens that grant indefinite access

  • Step 3: Persistent Access


    With captured tokens, attackers gain:

  • Direct access to the developer's SaaS accounts
  • Ability to modify repositories, deployments, and infrastructure
  • Access to secrets stored in connected systems
  • Ability to commit malicious code to production pipelines

  • ### Proof of Concept


    Mitiga demonstrated the vulnerability using a controlled lab environment where they:

    1. Set up a man-in-the-middle position between Claude Code and legitimate MCP servers

    2. Successfully captured OAuth tokens during normal MCP operations

    3. Used those tokens to access GitHub repositories and cloud platforms

    4. Demonstrated that API audit logs showed legitimate-looking activity, not obviously malicious requests


    The research found that token interception can occur even with HTTPS encryption if the attacker controls certificate validation (through compromised CA certificates or missing certificate pinning in the MCP implementation).


    ## Implications


    ### Immediate Risk Landscape


    For Individual Developers

  • Compromised development accounts could lead to malicious code commits
  • Access to personal projects, credentials, and intellectual property
  • Potential identity theft using developer credentials
  • Supply chain attacks where legitimate developers unknowingly push malicious code

  • For Organizations

  • Developers' tokens could provide entry points to corporate infrastructure
  • Access to source code repositories and deployment pipelines
  • Ability to exfiltrate proprietary code and trade secrets
  • Potential for inserting backdoors into released software

  • For SaaS Providers

  • Increased support burden handling compromised tokens
  • Need for rapid token rotation and invalidation mechanisms
  • Risk of regulatory compliance violations if customer data is exposed through compromised accounts
  • Potential liability for cascade compromises

  • ### Supply Chain Implications


    This vulnerability exemplifies a broader risk in AI-assisted development: trusted intermediaries can become attack surface. When developers delegate tasks to AI tools that integrate with their infrastructure, they're creating new dependency chains. A single vulnerability in MCP can expose:


  • Source code repositories
  • Infrastructure-as-code configurations
  • API keys and secrets
  • Deployment credentials
  • Database access tokens

  • ## Recommendations


    ### For Claude Code Users


    Immediate Actions

  • Audit all connected MCP integrations and disable unnecessary ones
  • Rotate all OAuth tokens and API keys used with Claude Code
  • Review recent commit history and deployments for unauthorized changes
  • Check audit logs in connected services (GitHub, AWS, Google Cloud) for suspicious activity

  • Short-Term Mitigations

  • Use network security controls (VPN, corporate proxy) when using Claude Code
  • Enable multi-factor authentication (MFA) on all connected SaaS platforms
  • Use short-lived tokens and implement automatic token rotation
  • Monitor API usage patterns for anomalies

  • Long-Term Security

  • Implement certificate pinning in MCP clients to prevent MITM attacks
  • Use dedicated service accounts with minimal permissions for Claude Code integrations
  • Separate development and production credentials
  • Implement network segmentation to isolate development traffic
  • Deploy intrusion detection systems that can identify suspicious token usage

  • ### For Anthropic/Claude Code Development Team


    Protocol Hardening

  • Implement mutual TLS authentication between Claude Code and MCP servers
  • Add token binding mechanisms that tie tokens to specific client identities
  • Implement automatic token expiration and rotation policies
  • Add cryptographic signing to verify MCP server authenticity

  • Monitoring and Detection

  • Implement behavioral anomaly detection for token usage
  • Create real-time alerting for tokens used from unexpected locations
  • Log all MCP operations for forensic analysis
  • Provide developers with token usage dashboards

  • Standards and Transparency

  • Publish security guidelines for MCP implementation
  • Establish clear threat models and security assumptions
  • Work with security researchers through responsible disclosure
  • Consider threat modeling workshops with the security community

  • ### For Security Teams and DevOps


  • Implement conditional access policies that flag Claude Code token usage
  • Monitor for unexpected SaaS API activity from development accounts
  • Require code review and approval for changes made through AI-assisted tools
  • Implement SIEM rules for detecting unusual token authentication patterns
  • Conduct security awareness training around AI tool usage risks

  • ## HackWire Analysis


    This vulnerability highlights a critical blind spot in how we secure the AI-assisted development pipeline. Unlike traditional access control vulnerabilities, the MCP hijacking attack is not about weak passwords or misconfigured permissions—it's about trusting a tool to handle your credentials properly.


    What makes this particularly concerning is the pattern it reveals: as organizations increasingly adopt AI-assisted development tools, they're creating new attack surfaces that don't fit into traditional security models. A developer using Claude Code isn't just using a text editor—they're delegating authentication decisions to an external system. That system becomes an attractive target precisely because it has legitimate access to valuable resources.


    The broader implication is that supply chain risk in software development is shifting from dependencies (third-party libraries) to development tools themselves. If an attacker compromises Claude Code's MCP layer, they don't need to inject code into a library—they can inject it directly into production repositories through developers' own legitimate credentials. This is arguably more dangerous because detection is harder and attribution is obscured.


    The research also exposes assumptions that many cloud platforms make about token security: that tokens are protected in transit and that strong encryption alone is sufficient. But tokens are only as secure as their weakest point of handling—in this case, the MCP protocol's assumptions about network trust. This should prompt broader conversations about how SaaS providers authenticate API clients and how they can better detect anomalous usage patterns.


    For defenders, the key lesson is that adopting AI-assisted development tools requires *additional* security controls, not fewer. The convenience of having Claude Code handle integrations doesn't eliminate the need for monitoring, token rotation policies, and network segmentation. If anything, it makes those controls more critical.


    — HackWire Editorial


    ## Key Takeaways


    | Aspect | Details |

    |--------|---------|

    | Vulnerability Type | OAuth token interception via MCP man-in-the-middle |

    | Attack Vector | Network-level interception, DNS hijacking, compromised proxies |

    | Primary Risk | Persistent unauthorized access to SaaS platforms and infrastructure |

    | Affected Users | Claude Code users with active MCP integrations |

    | Difficulty | Requires network-level access but leaves minimal forensic traces |

    | Detectability | Low—legitimate-looking API activity masks the compromise |


    ---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)