Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking) — Threadlinqs Intelligence
As of 2026-06-30, Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking) is a critical-severity supply chain threat attributed to Unnamed, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1012 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: Unnamed · FINANCIAL
Adversarial actors exploit AI coding agents (Claude Code, GitHub Copilot, Cursor, Codeium, Gemini CLI) via malicious bug reports, GitHub issues, and comments injected with prompt-injection payloads
Fake bug report attacks represent a novel class of supply-chain compromise leveraging the implicit trust between developers and AI coding assistants. Rather than embedding malicious code directly in repositories, attackers craft realistic-looking GitHub issues, pull request descriptions, and code comments containing prompt-injection payloads formatted as legitimate error reports or suggested fixes. When AI agents process these external data sources, injected instructions override user intent, triggering automated execution of arbitrary shell commands, exfiltration of environment variables (containing secrets and credentials), modification of security configurations (disabling approval prompts), and propagation of malware through npm, GitHub Actions, and MCP servers.
Key exploit chains include: (1) SymJack: symlink-hijacking in project files to redirect MCP server loads; (2) RoguePilot: malicious Copilot instructions embedded in GitHub issue bodies that influence generated code; (3) Agentjacking: formatted fake error messages that appear as legitimate AI-suggested fixes; (4) Comment and Control: prompt injection delivered via PR titles, issue descriptions, and comment threads; (5) Clinejection: GitHub Actions cache poisoning + indirect prompt injection in AI-driven issue triage leading to npm token theft and malware publication; (6) Clean Repo Attack: repositories with no malicious code trigger AI agent error-recovery behavior, enabling code execution without user awareness.
The Miasma worm campaign (June 2026) deployed a 4.3 MB self-replicating payload across 73 Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs), automatically triggering credential-harvesting when repositories opened in AI coding tools. A parallel campaign identified 10,000+ fake repositories—clones of popular projects injected with malicious instructions, auto-updating hourly to evade detection.
Defenses have proven insufficient: academic research (arXiv 2509.05372) evaluates LlamaGuard, PromptGuard, and Granite-Guardian, concluding that prompt injection may be structurally unfixable rather than patchable. Organizations must assume AI coding agents are insider threats until proven otherwise, implementing defense-in-depth controls: credential rotation, principle-of-least-privilege permissions for agents, continuous behavioral monitoring, sandboxed execution, human-in-the-loop approval workflows, and ongoing audit logging.
Target sectors: technology, software-development, cloud-computing, financial-services, government administration, health, ecommerce
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1190, T1195, T1566, T1059, T1059, T1059, T1556, T1078, T1550, T1140