threat-intel Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets A malicious tool server leveraging the Model Context Protocol (MCP) can silently exfiltrate sensitive data – including SSH keys, source code, and customer data – from AI coding assistants. The attack works by splitting requests into fragments and letting the agent stitch them together, even if individual fragments appe… The Hacker News · Aug 11, 2026 High aimodel context protocolghostsplice