Researchers at Mitiga Labs recently demonstrated a five-step attack that quietly hijacks Claude Code’s Model Context Protocol (MCP) traffic and steals the OAuth bearer tokens that grant access to platforms like Jira, Confluence, and GitHub. The attack needs no privilege escalation, no memory corruption, and no new CVE. It abuses the way an agentic developer […] The post When the Token Theft Hides in Plain Sight: Why Agent Containment Stops the Claude Code MCP Attack appeared first on Cequence Security .