{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:14:59Z","timestamp":1783437299612,"version":"3.54.6"},"publisher-location":"Singapore","reference-count":33,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819546732","type":"print"},{"value":"9789819546749","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T00:00:00Z","timestamp":1764028800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T00:00:00Z","timestamp":1764028800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-4674-9_17","type":"book-chapter","created":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T11:12:20Z","timestamp":1763982740000},"page":"329-349","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Supply Chain Threats in\u00a0the\u00a0MCP Ecosystem: Attack Vectors and\u00a0Mitigation Strategies"],"prefix":"10.1007","author":[{"given":"Yonghwa","family":"Lee","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wonseok","family":"Choi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Donghyun","family":"Nam","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,11,25]]},"reference":[{"key":"17_CR1","unstructured":"Anthropic: Introducing the model context protocol. Anthropic Announcement (2024). Available: https:\/\/www.anthropic.com\/news\/model-context-protocol"},{"key":"17_CR2","unstructured":"Anthropic: Model context protocol: Technical overview v0.9. Anthropic Technical Whitepaper (2024). Available: https:\/\/www.anthropic.com\/research\/model-context-protocol-overview"},{"key":"17_CR3","unstructured":"Apiiro Security: Malicious code campaign uncovered on Github\u2014repo confusion attack. Apiiro Blog (2025). Available: https:\/\/apiiro.com\/blog\/malicious-code-repo-confusion"},{"key":"17_CR4","unstructured":"Bergmann, D., Stryker, C.: What is langchain? IBM Data and AI Blog (2023). Available: https:\/\/www.ibm.com\/think\/topics\/langchain"},{"key":"17_CR5","unstructured":"Birsan, A.: Dependency confusion: how i hacked into apple, microsoft and dozens of other companies. Medium (personal blog) (2021). Available: https:\/\/medium.com\/@alex.birsan\/dependency-confusion-4a5d60fec610"},{"key":"17_CR6","unstructured":"Brown, T.B., et\u00a0al.: Language models are few-shot learners. In: Advances in Neural Information Processing Systems (NeurIPS), vol.\u00a033, pp. 1877\u20131901 (2020)"},{"key":"17_CR7","unstructured":"Cursor: Rce via prompt injection into cursor\u2019s terminal CMD-K. GitHub Repository (2024). Available: https:\/\/github.com\/brandondocusen\/CntxtPY"},{"key":"17_CR8","unstructured":"Cursor Community: Enhance MCP and native tool security (feature request). Cursor Community Forum Post (2025). Available: https:\/\/forum.cursor.com\/t\/enhance-mcp-security\/76324"},{"key":"17_CR9","unstructured":"Digmi, I.: The rising trend of malicious packages in open source ecosystems. Snyk Security Blog (2025). Available: https:\/\/snyk.io\/blog\/malicious-packages-open-source-ecosystems. (editor\u2019s note updated 2025)"},{"key":"17_CR10","unstructured":"Docusen, B.: Cntxtpy: Codebase knowledge-graph generator for python. GitHub Repository (2023). Available: https:\/\/github.com\/brandondocusen\/CntxtPY"},{"key":"17_CR11","unstructured":"Dong, Y., Mu, R., Jin, G., et\u00a0al.: Building guardrails for large language models. arXiv preprint arXiv:2402.01822 (2024)"},{"key":"17_CR12","unstructured":"Google: Announcing the agent2agent protocol (a2a). Google for Developers post (2025). Available: https:\/\/developers.googleblog.com\/en\/a2a-a-new-era-of-agent-interoperability\/"},{"key":"17_CR13","unstructured":"Gozadinos, G.: oterm: A highly extensible terminal-based UI library for python (2022). Available: https:\/\/github.com\/ggozad\/oterm"},{"key":"17_CR14","unstructured":"Hoodlet, K.: Insecure credential storage plagues MCP. Trail of Bits Technical Blog (2025). Available: https:\/\/blog.trailofbits.com\/2025\/04\/30\/insecure-credential-storage-plagues-mcp\/"},{"key":"17_CR15","unstructured":"Hou, X.: Name collisions and impersonation risks in MCP tool registries. Personal Security Blog (2025). Available: https:\/\/security.example.com\/mcp-name-collision-analysis"},{"key":"17_CR16","unstructured":"idoubi: Mcp.so - the largest collection of MCP servers, featuring awesome MCP servers and Claude MCP integration (2025). https:\/\/mcp.so\/"},{"key":"17_CR17","unstructured":"InjectPrompt: Claude sonnet 4 jailbreak via narrative tool injection (2024). Available: https:\/\/www.injectprompt.com\/p\/claude-sonnet-4-jailbreak-narrative-tool-injection"},{"key":"17_CR18","unstructured":"Invariant Labs: Mcp security notification: Tool poisoning attacks. Invariant Labs Blog (2025). Available: https:\/\/invariantlabs.ai\/blog\/mcp-security-notification-tool-poisoning-attacks"},{"key":"17_CR19","unstructured":"Kowejsza, L.: The rise and fall of (autonomous) agents. Medium (personal blog) (2024). Available: https:\/\/medium.com\/@lukas.kowejsza\/the-rise-and-fall-of-autonomous-agents-18360625067e"},{"key":"17_CR20","unstructured":"Larson, S.: Supply-chain attack analysis: Ultralytics. PyPI Official Blog (2024). Available: https:\/\/blog.pypi.org\/posts\/2024-12-11-ultralytics-attack-analysis\/"},{"key":"17_CR21","unstructured":"McCarthy, R.: Research briefing: Mcp security. Wiz Research Blog (2025). Available: https:\/\/www.wiz.io\/blog\/mcp-security-research-briefing"},{"key":"17_CR22","unstructured":"Model Context Protocol: MCP python SDK. Model Context Protocol Announcement (2024). Available: https:\/\/github.com\/modelcontextprotocol\/python-sdk"},{"key":"17_CR23","unstructured":"Model Context Protocol Registry: a community driven registry service for model context protocol (mcp) servers (2025). https:\/\/github.com\/modelcontextprotocol\/registry"},{"key":"17_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-030-52683-2_2","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"M Ohm","year":"2020","unstructured":"Ohm, M., Plate, H., Sykosch, A., Meier, M.: Backstabber\u2019s knife collection: a review of open source software supply chain attacks. In: Maurice, C., Bilge, L., Stringhini, G., Neves, N. (eds.) DIMVA 2020. LNCS, vol. 12223, pp. 23\u201343. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-52683-2_2"},{"key":"17_CR25","unstructured":"OWASP Foundation: Top 10 security risks for large language model applications. OWASP Project Report (2023). Available: https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/"},{"key":"17_CR26","unstructured":"SafeDep: Dynamic malware analysis of open-source packages at scale. SafeDep Research Blog (2025). Available: https:\/\/safedep.io\/blog\/dynamic-analysis-oss"},{"key":"17_CR27","unstructured":"Shankar, S.: Everything wrong with mcp. SSHH Security Blog (2025). Available: https:\/\/blog.sshh.io\/p\/everything-wrong-with-mcp"},{"key":"17_CR28","unstructured":"Sharma, M., et\u00a0al.: Constitutional classifiers: Defending against universal jailbreaks across thousands of hours of red teaming. arXiv preprint arXiv:2501.18837 (2025). https:\/\/arxiv.org\/abs\/2501.18837"},{"key":"17_CR29","unstructured":"Smithery AI: Smithery - model context protocol registry (2025). https:\/\/smithery.ai\/"},{"key":"17_CR30","unstructured":"Spracklen, J., et\u00a0al.: We have a package for you! a comprehensive analysis of package hallucinations by code generating llms. arXiv preprint arXiv:2406.10279 (2024). https:\/\/arxiv.org\/abs\/2406.10279"},{"key":"17_CR31","unstructured":"Titterington, A.: Supply-chain attacks in 2024. Kaspersky Security Blog (2025). Available: https:\/\/www.kaspersky.com\/blog\/supply-chain-attacks-in-2024\/52965\/"},{"key":"17_CR32","unstructured":"Trail of Bits: Jumping the line: How MCP servers can attack you before you ever use them. Trail of Bits Technical Blog (2025). Available: https:\/\/blog.trailofbits.com\/2025\/04\/21\/jumping-the-line-how-mcp-servers-can-attack-you-before-you-ever-use-them\/"},{"key":"17_CR33","unstructured":"Yao, S., Zhao, J., Du, N., et\u00a0al.: React: Synergizing reasoning and acting in language models. In: International Conference on Learning Representations (2023)"}],"container-title":["Lecture Notes in Computer Science","Advances in Information and Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-4674-9_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T14:31:44Z","timestamp":1783434704000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-4674-9_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,25]]},"ISBN":["9789819546732","9789819546749"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-4674-9_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,25]]},"assertion":[{"value":"25 November 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IWSEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Fukuoka","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 November 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 November 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iwsec2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.iwsec.org\/2025\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}