[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYKEtGL49N6DsbjyfA_O_ZEaoLz5tBRIf0aINihN64EM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"3f8d16c6-d591-4ceb-b0dc-aa6adf9db6d2","ai-coding-agents-manipulated-into-running-malware-via-poisoned-github-repos","02df979d-6647-458a-bd5f-2bc00b41997a","AI Coding Agents Manipulated Into Running Malware via Poisoned GitHub Repos","Attackers crafted clean-looking GitHub repositories with malicious setup instructions designed to exploit the autonomous execution behavior of AI coding agents like Claude Code. Because these agents follow natural language instructions without fully understanding malicious intent, a seemingly benign README or setup script can trigger a full reverse shell. This attack bypasses traditional static scanners and human code review since the repository itself appears legitimate — the danger lies in the instructions, not the code. It highlights a critical trust gap: AI agents are being granted significant system privileges without sufficient guardrails around the commands they execute. As AI-assisted development accelerates, this class of 'prompt injection via repository' attack represents a growing and underappreciated supply chain risk.","**Immediate actions:**\n- Restrict AI coding agent permissions to sandboxed, isolated environments with no direct internet or shell access by default.\n- Audit all AI agent integrations to identify which have unrestricted command execution capabilities and limit their scope immediately.\n\n**Long-term improvements:**\n- Implement a policy requiring human review and approval before any AI agent executes setup scripts, install commands, or shell instructions from external repositories.\n- Treat third-party repositories consumed by AI agents as untrusted supply chain inputs and apply the same vetting process as third-party libraries.\n- Develop and enforce an AI agent usage policy that defines acceptable autonomy levels, permitted actions, and escalation triggers.\n\n**Detection measures:**\n- Deploy runtime behavioral monitoring on systems where AI agents operate to detect anomalous outbound connections, reverse shells, or unexpected process spawning.\n- Log all commands executed by AI agents with full context and alert on any network egress initiated by agent-driven processes.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 10: Malware Defenses","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 AU-12: Audit Record Generation","NIST AI RMF: Govern 1.2 – AI Risk Policies","OWASP LLM Top 10: LLM01 – Prompt Injection","SLSA Supply Chain Levels for Software Artifacts – Source Integrity","published","2026-06-27T16:20:20.922606+00:00","2026-06-27T16:20:20.711+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fclean-github-repo-tricks-ai-coding-agents-into-running-malware\u002F","clean-github-repo-tricks-ai-coding-agents-into-running-malware-de5675","Clean GitHub repo tricks AI coding agents into running malware",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49,55],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"d84c9cab-0223-4a8d-afce-6c2f2f6c14cc","2026-06-29","morning","ThreatNoir Morning Brief — June 29","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-29\u002Fthreatnoir-morning-brief-2026-06-29.mp3",{"id":56,"date":57,"edition":52,"title":58,"audio_url":59},"94c85689-e16e-4d0f-8610-284e3f498200","2026-06-28","ThreatNoir Weekend Brief — June 28","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-28\u002Fthreatnoir-morning-brief-2026-06-28.mp3"]