Agentjacking: AI Coding Agents Tricked Into Running Maliciou
🟠 High | Source: The Hacker News A newly identified attack technique called ‘Agentjacking’ manipulates AI coding agents — such as those integrated into developer IDEs — into executing malicious code on developer machines. The attack is triggered by injecting a crafted fake error report via Sentry, a widely used error-tracking platform, which the AI agent then acts upon without sufficient validation. This is significant because AI coding agents operate with broad system permissions and are increasingly prevalent in software development workflows. ...