18,883 MCP servers. Five Chinese tech giants joined this week. Zero security audits.
On March 24, someone put malware in litellm, a popular Python library for calling LLM APIs. Versions 1.82.7 and 1.82.8 on PyPI stole API keys for OpenAI, Anthropic, and Gemini. Two Hacker News post...

Source: DEV Community
On March 24, someone put malware in litellm, a popular Python library for calling LLM APIs. Versions 1.82.7 and 1.82.8 on PyPI stole API keys for OpenAI, Anthropic, and Gemini. Two Hacker News posts about it got 1,159 points total and 364 comments. The same week, five Chinese tech companies appeared on the MCP.so trending page. Tencent, Zhipu AI, Amap (owned by Alibaba), Baidu, and MiniMax. They all published MCP servers between March 23 and 25. The total number of MCP servers has now reached 18,883. Everyone noticed litellm. Nobody noticed the Chinese MCP servers. No security review. No public discussion. Nothing. MCP has the same supply chain problem as npm, but worse npm's supply chain attacks are well known. event-stream in 2018. ua-parser-js in 2021. MCP is heading down the same path, but with two differences that make it worse. The first is data direction. When you install an npm package, code runs on your machine. It stays local. When you connect an MCP server, your data leaves