MCP OAuth Phishing in VS Code: technical analysis and June 2026 context
The MCP OAuth phishing attack exploits VS Code's automatic authentication flow. No vulnerabilities are required: the protocol works exactly as designed. Analysis of the mcp-phish-poc, remote exploitation, and the cascade of MCP security findings in June 2026: Axios hijack, mcp-remote RCE, Claude Code token theft, CVE-2026-41613, and the GitHub breach by TeamPCP.