Italiano(IT)⚠️ Anche repo GitHub “puliti” possono diventare un vettore: agenti AI troppo autonomi rischiano di installare malware. Fiducia sì, ma con sandbox e controlli. #
干净的GitHub仓库被武器化,诱骗AI编码代理运行恶意软件
作者PulseAugur 编辑部·[11 个来源]·
研究人员发现了一种新颖的攻击载体,看似干净的GitHub仓库会诱骗AI编码代理执行隐藏的恶意软件。该方法利用了代理的自动化设置过程,使得恶意负载对安全扫描器、AI代理和人工审查者都保持不可见。攻击链涉及一系列间接步骤,从仓库设置流程中的错误消息开始,AI代理可能会将其解释为常规恢复操作,最终导致执行从攻击者控制的DNS记录中检索到的命令。
AI
Claude and other AI agents fooled into running malware with just a minimal GitHub repository — ask the bot to initialize the project and you get hacked
dev.to — Claude Code tag
TIER_1English(EN)·XOOMAR·
<p>A <strong>clean GitHub repo</strong> can give an attacker an interactive shell on a developer’s machine if an <strong>AI coding agent</strong> is allowed to “fix” setup errors on its own. That risk lands hardest on builders using tools such as <strong>Claude Code</strong> to c…
AI coding agents can be tricked into installing malware via 'clean' GitHub repositories — Mozilla's 0din team shows how Claude Code can be exploited by its own helpfulness Claude and other AI agents fooled into running malware with just a minimal GitHub repository — ask the bot t…
Clean GitHub repo tricks AI coding agents into running malware An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. # AI https:…
Claude Code kann laut 0DIN versteckten Schadcode aus einem manipulierten GitHub-Repo ausführen, wenn es ein Projekt einrichtet. Für Teams, die KI-Coding-Tools einsetzen, ist das ein direktes Supply-Chain-Risiko. https:// the-decoder.de/harmloser-githu b-link-wird-zur-falle-claude…
⚠️ Anche repo GitHub “puliti” possono diventare un vettore: agenti AI troppo autonomi rischiano di installare malware. Fiducia sì, ma con sandbox e controlli. # Cybersecurity # AI 🔗 https://www. tomshw.it/hardware/gli-agenti- ai-possono-installare-malware-da-repository-github-pul…
🤖 Novel attack vector: clean GitHub repos can trick AI coding agents (Cursor, Copilot, Codex) into running hidden malware. The payload remains invisible to security scanners, AI agents, and human reviewers. A new supply-chain risk for AI-assisted development. 🔗 https://www. bleep…
🤖 Clean GitHub repos are being weaponized against AI coding agents. A benign-looking repo can execute a payload that evades scanners, AI agents, and human review — turning agentic tools into malware vectors. 🔗 https://www. bleepingcomputer.com/news/secu rity/clean-github-repo-tri…