Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Malicious GitHub Repositories Could Trick AI Coding Agents Into Running Hidden Malware, Researchers Warn

Дата публикации: 28-06-2026 06:05:59

Researchers warn malicious GitHub repositories can trick AI coding agents into running hidden malware through trusted setup steps, risking developer systems and credentials.

Основное содержимое страницы с новостью.

A newly demonstrated attack technique shows how malicious GitHub repositories could manipulate AI-powered coding assistants into executing hidden malware without embedding any malicious code in the repository itself.

The proof-of-concept, detailed by researchers at Mozilla's Zero Day Investigative Network (0DIN), highlights a potential supply chain risk for developers increasingly relying on autonomous coding agents.

Here, it should be noted that, as previously reported, GitHub began an investigation after claims of unauthorized access to its internal repositories, following the hacker group TeamPCP's alleged theft of nearly 4,000 private source code repositories.

The platform said it is reviewing the incident, but currently has no evidence that customer data stored outside its internal repositories has been affected. It added that any impacted customers would be notified if the investigation uncovers signs of external compromise.

The claims surfaced on the Breached cybercrime forum, where TeamPCP alleged it had obtained GitHub's source code and internal organizational data and was offering it for sale for at least $50,000. The group claimed it was not seeking a ransom and threatened to leak the data publicly if no buyer emerged.

Attack Uses Trusted Setup Steps Instead of Exploits

According to a recent report by BleepingComputer, the attack targets agentic coding tools that automatically clone and configure GitHub projects. Rather than exploiting a software vulnerability, the technique leverages seemingly routine setup instructions to trigger a hidden attack chain.

Researchers said the compromise occurs with "no exploit code, no warning, no suspicious command anyone had to approve".

The demonstration used Anthropic's Claude Code, showing how the AI assistant could be prompted to execute a malicious payload while attempting to resolve what appeared to be a standard project setup error.

Importantly, the GitHub repository itself contained no malicious code that would typically alert security scanners, AI systems, or human reviewers.

Microsoft reports an active cyber campaign targeting hotels in Europe and Asia using fake photo ZIPs, PowerShell malware, and Node.js implants with evolving evasion tactics.magnific.com
Three-Step Chain Hides the Malicious Payload

The attack relies on three individually benign components working together.

First, the repository presents standard installation and initialization commands that appear legitimate. Second, a Python package is intentionally designed to fail until initialized, prompting an error message instructing users, or an AI coding agent, to run an initialization command.

Finally, that initialization process invokes a shell script that retrieves a configuration value from an attacker-controlled DNS TXT record and executes it as a command.

According to the researchers, the AI agent automates the entire sequence while attempting to fix what it perceives as a normal configuration problem.

"Claude Code never decided to open a shell. It decided to fix an error. The reverse shell is three indirection steps away from anything Claude Code actually evaluated: an error message it trusted, a script that fetched a value, and a DNS record it never saw," the 0DIN researchers explained.

They added, "The attacker now has an interactive shell running as the developer's own user."

Researchers Recommend Greater Transparency for AI Agents

Although the technique remains a proof of concept, the researchers cautioned that attackers could distribute such repositories through fake job offers, technical tutorials, blog posts, or direct messages to developers.

If successful, the attack could give threat actors access to a developer's environment variables, API keys, local configuration files, and other sensitive resources while enabling long-term persistence on the compromised system.

To reduce the risk, 0DIN recommends that AI coding agents disclose the complete execution chain behind setup operations, including any scripts or code retrieved dynamically at runtime.

The researchers argue that greater transparency would help developers identify hidden execution paths before AI assistants automatically perform potentially dangerous actions.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets-2711-07-2026
2A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots07.421-07-2026
3Malicious AI Coding Plugins Hit JetBrains Marketplace, Stealing API Keys From Developers-2817-06-2026
4Fake-GitHub-Repositorys: Infostealer statt Security- oder Developer-Tools-2615-07-2026
5Microsoft’s open source tools were hacked to steal passwords of AI developers-2608-06-2026
6Cursor AI's Silence on a Critical Flaw Jeopardizes Millions of Users-5715-07-2026
7Compromised VS Code Extension Puts Linux Development Pipelines at Risk0703-06-2026
8GitHub Actions Compromise CI/CD Supply Chain Risks Explored0826-05-2026
9New GitHub Zero-Day Exposed Developer Tokens to Attackers-5704-06-2026
10Several npm repositories compromised0501-06-2026

Классификация: Наука. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7. Источник: www.ibtimes.sg.