Clean GitHub repo tricks AI coding agents into running malware
A newly discovered vulnerability in AI-powered coding tools has left security experts sounding the alarm. Researchers at Mozilla’s Zero Day Investigative Network (0DIN) have demonstrated a method by which an attacker can plant malware on a developer’s device without leaving any suspicious code or exploit in the repository. The attack relies on a seemingly innocuous-looking … Read more