Suspicious Malicious MCP Package devtools-assistant Execution (via process_creation)

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects installation or execution of the devtools-assistant package a trojanized MCP server used in a supply-chain attack against AI development tooling. Once run it enumerates and exfiltrates developer credentials from files such as .env .aws and .ssh. Catching the pip install or python module invocation flags the compromise at the point of execution.

Related detections9 linkedT1059.006 — drag to rearrange
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Linux process chain for Axios NPM compromise: curl download with nohup and python3
Suspicious Execution From Hidden fonts-unix Directory in tmp on Linux
Malicious GitVenom Python Fernet Decrypt-and-Execute Loader via process_creation
Suspicious Python Executing Script from var root Library Caches on macOS (via process_creation)
Suspicious Python Script Persistence in User Startup Folder
Suspicious Bun Runtime Spawned by Node During npm Lifecycle
Malicious SolarWinds BusinessLayerHost Spawning Command Interpreter
Suspicious Malicious MCP Package devtools-assistant Execution (via process_creation)
Pivot detection · T1059.006 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.