AutoJack: How a single page can RCE the host running your AI agent

2026-06-21T14:52:20Z1ae12838a218d2007855155ae0a481d0b88d1266b3d95a5a963929cc4f27b09a
agentic-browsingai-agentai-investigationsassertautogen-studioautojackclipboard-theftcrypto-clipperlocalhost-trustmastramcp-websocketmdashmicrosoft-securitymissing-authenticationnpmpostinstall-payloadrceremote-code-executionsupply-chaintorweb-exploitworm-propagation

What happened

The feed highlights a critical new exploit, “AutoJack,” where a single malicious webpage can achieve remote code execution on the host running an AI browsing agent by abusing trust in localhost, missing authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket—demonstrating a broader class of risks when agents browse untrusted content and can reach local services. Additional posts cover a poisoned npm package (Mastra) that infected 140+ projects via a postinstall payload (supply-chain compromise), a crypto-clipper campaign using Tor and worm-like propagation for clipboard

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
1ae12838a218d2007855155ae0a481d0b88d1266b3d95a5a963929cc4f27b09a
Enrichment time
2026-06-21T14:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.