Why it matters
XLab observed the Go-based NadMesh botnet scan internet-exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio, and MCP services for cloud keys, Kubernetes tokens, Docker credentials, and callable tools. MCP command execution appeared in observed traffic, although most exploitation targeted conventional Docker and Jenkins exposures and the operator dashboard’s scale claims were internally inconsistent.
My takeaway: The AI label does not change the root controls: keep development services and MCP endpoints off the public internet, require authentication, remove ambient secrets, enforce least privilege, restrict command-capable tools, rotate exposed credentials, and monitor unusual scans, container creation, and token use.