# Claude Code OAuth Tokens Exposed: Critical MCP Hijacking Vulnerability Reveals Supply Chain Risk in AI Development Tools
Researchers at Mitiga have discovered a critical vulnerability that allows attackers to silently intercept OAuth tokens from Claude Code users by hijacking Model Context Protocol (MCP) traffic. The attack enables persistent access to connected SaaS platforms and represents a significant supply chain security gap in the growing ecosystem of AI-assisted development tools.
## The Threat
Claude Code, Anthropic's integrated development environment for AI-assisted software engineering, integrates with multiple cloud services and APIs through MCP—a protocol that enables Claude to interact with external systems. Mitiga's research reveals that attackers can intercept OAuth tokens transmitted through this protocol channel, potentially gaining unauthorized access to a developer's connected services without triggering security alerts.
The vulnerability is particularly concerning because:
## Background and Context
### What Is Model Context Protocol?
Model Context Protocol is a standardized interface that allows AI assistants to safely interact with external systems, databases, and APIs. Rather than embedding service-specific logic directly into Claude, MCP acts as a middleware layer that manages these connections.
For Claude Code users, MCP enables features like:
### The MCP Architecture Gap
While MCP was designed with security in mind, the research identifies a critical assumption: that the communication channel between Claude Code and MCP servers is inherently trusted. This assumption breaks down when attackers can position themselves between the client and the MCP endpoint.
The vulnerability stems from insufficient validation of:
## Technical Details
### How the Attack Works
Step 1: Traffic Interception
Attackers can intercept MCP traffic through multiple vectors:
Step 2: Token Extraction
Once traffic is intercepted, attackers can:
Step 3: Persistent Access
With captured tokens, attackers gain:
### Proof of Concept
Mitiga demonstrated the vulnerability using a controlled lab environment where they:
1. Set up a man-in-the-middle position between Claude Code and legitimate MCP servers
2. Successfully captured OAuth tokens during normal MCP operations
3. Used those tokens to access GitHub repositories and cloud platforms
4. Demonstrated that API audit logs showed legitimate-looking activity, not obviously malicious requests
The research found that token interception can occur even with HTTPS encryption if the attacker controls certificate validation (through compromised CA certificates or missing certificate pinning in the MCP implementation).
## Implications
### Immediate Risk Landscape
For Individual Developers
For Organizations
For SaaS Providers
### Supply Chain Implications
This vulnerability exemplifies a broader risk in AI-assisted development: trusted intermediaries can become attack surface. When developers delegate tasks to AI tools that integrate with their infrastructure, they're creating new dependency chains. A single vulnerability in MCP can expose:
## Recommendations
### For Claude Code Users
Immediate Actions
Short-Term Mitigations
Long-Term Security
### For Anthropic/Claude Code Development Team
Protocol Hardening
Monitoring and Detection
Standards and Transparency
### For Security Teams and DevOps
## HackWire Analysis
This vulnerability highlights a critical blind spot in how we secure the AI-assisted development pipeline. Unlike traditional access control vulnerabilities, the MCP hijacking attack is not about weak passwords or misconfigured permissions—it's about trusting a tool to handle your credentials properly.
What makes this particularly concerning is the pattern it reveals: as organizations increasingly adopt AI-assisted development tools, they're creating new attack surfaces that don't fit into traditional security models. A developer using Claude Code isn't just using a text editor—they're delegating authentication decisions to an external system. That system becomes an attractive target precisely because it has legitimate access to valuable resources.
The broader implication is that supply chain risk in software development is shifting from dependencies (third-party libraries) to development tools themselves. If an attacker compromises Claude Code's MCP layer, they don't need to inject code into a library—they can inject it directly into production repositories through developers' own legitimate credentials. This is arguably more dangerous because detection is harder and attribution is obscured.
The research also exposes assumptions that many cloud platforms make about token security: that tokens are protected in transit and that strong encryption alone is sufficient. But tokens are only as secure as their weakest point of handling—in this case, the MCP protocol's assumptions about network trust. This should prompt broader conversations about how SaaS providers authenticate API clients and how they can better detect anomalous usage patterns.
For defenders, the key lesson is that adopting AI-assisted development tools requires *additional* security controls, not fewer. The convenience of having Claude Code handle integrations doesn't eliminate the need for monitoring, token rotation policies, and network segmentation. If anything, it makes those controls more critical.
— HackWire Editorial
## Key Takeaways
| Aspect | Details |
|--------|---------|
| Vulnerability Type | OAuth token interception via MCP man-in-the-middle |
| Attack Vector | Network-level interception, DNS hijacking, compromised proxies |
| Primary Risk | Persistent unauthorized access to SaaS platforms and infrastructure |
| Affected Users | Claude Code users with active MCP integrations |
| Difficulty | Requires network-level access but leaves minimal forensic traces |
| Detectability | Low—legitimate-looking API activity masks the compromise |
---