AutoJack: How a single page can RCE the host running your AI agent

2026-06-20T20:52:16Zb3b3ff7ad56eee41fc5cd1a3a5f2943f4d9a52831b6b9a80618e211d3eb980af
AI agentAI securityASSERTAutoGen StudioAutoJackMCP WebSocketMDASHMastraMicrosoft Defender benchmarkingRCESapphire SleetToragentic vulnerability detectionbackdoorclipboard theftcrypto clipperlocalhost trustmissing authenticationnpm compromiseopen sourcepostinstall payloadremote code executionsupply chain compromiseunsafe parameter handlingworm-like propagation

What happened

This Microsoft Security Blog feed highlights several high-impact security issues and research: 1) AutoJack — a novel single-page web exploit that can convert an AI browsing agent into a host Remote Code Execution (RCE) vector by abusing localhost trust, missing authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket, enabling arbitrary process execution on the host; 2) Mastra npm supply-chain compromise (Sapphire Sleet) that delivered a hidden postinstall payload and infected 140+ projects; 3) a Crypto Clipper campaign that steals clipboard data, substitutes crypto‑urls

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
b3b3ff7ad56eee41fc5cd1a3a5f2943f4d9a52831b6b9a80618e211d3eb980af
Enrichment time
2026-06-20T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AutoJack: How a single page can RCE the host running your AI agent · Baitaphish