Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking
Summary
Attackers can steal OAuth tokens (digital keys that grant access to connected services) from Claude Code, an AI system that performs tasks autonomously, through a man-in-the-middle attack (intercepting communication between two parties). The attack involves installing a malicious npm package that modifies Claude Code's configuration file to redirect all traffic through the attacker's infrastructure, allowing them to capture tokens while remaining undetected.
Classification
Affected Vendors
Related Issues
Original source: https://www.securityweek.com/claude-code-oauth-tokens-can-be-stolen-through-stealthy-mcp-hijacking/
First tracked: May 7, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%