Users could be tricked into running arbitrary code, but the issue was patched last week.
SmartLoader campaign spreading StealC via a trojanized Oura MCP server using fake GitHub forks to steal credentials and ...