ASSET Research Group, a security research lab, disclosed the GhostSplice technique that exploits MCP to split malicious instructions across channels, tricking AI coding agents into exfiltrating secrets. They also previously disclosed Ghostcommit, a similar attack using PNG files.