NadMesh Botnet Targets AI Infrastructure and MCP Services
AI development stacks increasingly rely on internet-accessible tools such as ComfyUI and Ollama, while Model Context Protocol services connect models with external data and applications. Poorly secured deployments can expose cloud credentials, model access and costly computing resources. NadMesh highlights how attackers are turning vulnerabilities across this expanding AI infrastructure into automated entry points, raising supply-chain risks for developers, cloud operators and companies deploying generative AI systems.
Security researchers recently disclosed that NadMesh is scanning at scale for vulnerable ComfyUI, Ollama and MCP services. The malware combines more than 20 remote-code-execution exploits to compromise exposed systems, steal cloud credentials and obtain access to AI models before spreading automatically. Researchers described the operation as an industrialized attack platform rather than a single-purpose malware campaign. The report did not provide a confirmed victim count, financial-loss estimate or specific disclosure date.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.