Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

A Silent Threat Lurks in Open-Source Code Repositories: Malicious .git Configs Can Hijack AI Agents

In a disturbing trend, cybersecurity researchers have uncovered a new attack vector that leverages seemingly innocuous open-source code repositories to compromise high-profile artificial intelligence (AI) agents. The malicious tactic involves exploiting the configuration files of popular AI tools like Claude, Codex, and Cursor, allowing attackers to inject arbitrary code into these systems.

This stealthy threat has been spotted in various open-source projects hosted on GitHub, where developers often share and collaborate on code. Specifically, hackers are targeting the .git config files used by these repositories, which contain sensitive information about the project’s dependencies and environment settings. By subtly modifying this configuration data, attackers can hijack the AI agents and execute malicious code on behalf of the compromised systems.

Researchers have demonstrated that this attack vector is particularly effective against large language models like Claude and Codex, which rely heavily on their configuration files to function properly. In one instance, a malicious .git config file was used to inject a Trojan horse into a popular open-source project, allowing an attacker to execute arbitrary code within the compromised system.

This alarming trend highlights the growing risk of supply chain attacks in the AI and machine learning ecosystems. As more organizations rely on these high-profile tools, the potential for disruption and data breaches increases exponentially. Moreover, the fact that attackers can hide their malicious activity within seemingly innocuous open-source projects underscores the need for enhanced security measures in this space.

To mitigate this threat, developers and system administrators must remain vigilant when collaborating on or consuming open-source code. Regularly reviewing configuration files and monitoring AI agent behavior for signs of tampering are essential steps in preventing these types of attacks. Furthermore, implementing robust access controls and auditing mechanisms can help identify and respond to potential security incidents in a timely manner.

As the cyber threat landscape continues to evolve, it’s crucial that organizations prioritize the security of their AI and machine learning infrastructure. By staying informed about emerging threats like this one and taking proactive measures to protect against them, we can mitigate the risk of devastating attacks on our critical systems.


Source: The Hacker News — 2026-09-02