The China-linked APT GopherWhisper has been using legitimate services and various Go-based backdoors in attacks.
A design choice in the MCP SDKs allows remote code execution across the AI supply chain.