Threat reportSupply ChainTL-2026-1012
Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking)
Fake Bug Report Prompt Injection Attacks Hijacking AI Coding (TL-2026-1012) is a critical-severity supply-chain compromise scored CVSS 9.8, first published 2026-06-30. It is attributed to Unnamed with medium confidence, maps to 21 MITRE ATT&CK techniques (T1020, T1021, T1027), and is covered by 9 detection rules and 26 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 1Unnamed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-1012
- Threat ID
- TL-2026-1012
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Unnamed
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cloud-computing, financial-services, government administration, health, ecommerce
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Fake Bug Report Prompt Injection Attacks Hijacking AI Coding
Malware and tooling: Miasma Worm, OpenClaw, Claude Code, Cline, Codeium, Cursor, DontRevokeOrItGoesBoom, Gemini CLI, GitHub Copilot, Grok Build CLI, TheBeautifulSandsOfTime, firedalazer
How Fake Bug Report Prompt Injection Attacks Hijacking AI Coding works
Adversarial actors exploit AI coding agents (Claude Code, GitHub Copilot, Cursor, Codeium, Gemini CLI) via malicious bug reports, GitHub issues, and comments injected with prompt-injection payloads that trigger remote code execution, credential theft, and supply-chain compromise. Multiple CVEs (CVE-2025-53773, CVE-2025-66032) and active campaigns (Miasma worm: 73+ Microsoft repos; 10,000+ fake repositories) demonstrate exploitation at scale.
Fake bug report attacks represent a novel class of supply-chain compromise leveraging the implicit trust between developers and AI coding assistants. Rather than embedding malicious code directly in repositories, attackers craft realistic-looking GitHub issues, pull request descriptions, and code comments containing prompt-injection payloads formatted as legitimate error reports or suggested fixes. When AI agents process these external data sources, injected instructions override user intent, triggering automated execution of arbitrary shell commands, exfiltration of environment variables (containing secrets and credentials), modification of security configurations (disabling approval prompts), and propagation of malware through npm, GitHub Actions, and MCP servers.
Key exploit chains include: (1) SymJack: symlink-hijacking in project files to redirect MCP server loads; (2) RoguePilot: malicious Copilot instructions embedded in GitHub issue bodies that influence generated code; (3) Agentjacking: formatted fake error messages that appear as legitimate AI-suggested fixes; (4) Comment and Control: prompt injection delivered via PR titles, issue descriptions, and comment threads; (5) Clinejection: GitHub Actions cache poisoning + indirect prompt injection in AI-driven issue triage leading to npm token theft and malware publication; (6) Clean Repo Attack: repositories with no malicious code trigger AI agent error-recovery behavior, enabling code execution without user awareness.
The Miasma worm campaign (June 2026) deployed a 4.3 MB self-replicating payload across 73 Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs), automatically triggering credential-harvesting when repositories opened in AI coding tools. A parallel campaign identified 10,000+ fake repositories—clones of popular projects injected with malicious instructions, auto-updating hourly to evade detection.
Defenses have proven insufficient: academic research (arXiv 2509.05372) evaluates LlamaGuard, PromptGuard, and Granite-Guardian, concluding that prompt injection may be structurally unfixable rather than patchable. Organizations must assume AI coding agents are insider threats until proven otherwise, implementing defense-in-depth controls: credential rotation, principle-of-least-privilege permissions for agents, continuous behavioral monitoring, sandboxed execution, human-in-the-loop approval workflows, and ongoing audit logging.
MITRE ATT&CK techniques used in TL-2026-1012
exfiltration
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1537 Transfer Data to Cloud Account
Collection
Execution
T1059 Command and Scripting Interpreter
Discovery
Credential Access
T1110 Brute Force; T1552 Unsecured Credentials
Initial Access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing
initial-access
Impact
lateral-movement
T1550 Use Alternate Authentication Material
Persistence
Timeline of Fake Bug Report Prompt Injection Attacks Hijacking AI Coding
- Johns Hopkins researchers disclose 'Comment and Control' prompt injection attack via GitHub PR titles, issue descriptions, and comment threads targeting AI agents including Claude Code, GitHub Copilot, and Gemini CLI.
- Miasma worm self-replicating supply-chain malware compromises 73 Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs). Deploys 4.3 MB credential-harvesting payload triggered on repository open in Claude Code, Gemini CLI, Cursor, VS Code.
- CVE-2025-53773 (GitHub Copilot RCE via Prompt Injection) publicly disclosed. Attack embeds instructions in code/comments to set 'chat.tools.autoApprove: true', disabling all user confirmations and enabling privileged shell execution.
- Microsoft releases August 2025 Patch Tuesday; CVE-2025-53773 patched. Configuration changes affecting security settings now require explicit user approval.
- arXiv paper 2509.05372 published: 'Adversarial Bug Reports as a Security Risk in LLM-Based Automated Program Repair'. Evaluates 51 adversarial bug reports across APR systems; concludes prompt injection may be structurally unfixable rather than patchable.
- Orca Security discloses RoguePilot vulnerability: GitHub Copilot processes malicious Copilot instructions embedded in GitHub Issues, allowing code generation influence via indirect prompt injection.
- Anthropic patches Claude Code GitHub Action vulnerabilities (v1.0.94+). Addresses checkWritePermissions function bypass that unconditionally trusted any actor ending in [bot]; resolves credential-exfiltration techniques.
- GMO Flatt Security researcher RyotaK demonstrates 'Poisoning Claude Code' attack: fake error message in GitHub issue body triggers arbitrary command execution, environment variable exfiltration, and CSRF bypass via issue comment rewrite.
- SecurityWeek publishes SymJack attack by Adversa AI: symlink-hijacking in MCP project configuration allows attacker-controlled MCP server injection via misleading approval prompts.
- Adnan Khan discloses 'Clinejection' vulnerability chain in Cline repository. GitHub Actions cache poisoning + AI-driven issue triage enables npm publish token theft; malicious Cline v2.3.0 published, installing OpenClaw agent on ~4,000 developer machines over 8-hour window.
- Tenet Threat Labs discloses Agentjacking attack framework: prompt injection via fake bug reports/error messages formatted to trigger AI-suggested fixes. Demonstrates hijacking with single text-only payload invisible to security controls.
- Follow-up research confirms Comment and Control attack scale: multiple AI agents (Claude Code, Gemini CLI, GitHub Copilot, Cursor) vulnerable to indirect prompt injection via GitHub infrastructure.
- Researchers document 'Clean Repo Attack' campaign: repositories with zero malicious code exploit AI agent error-recovery behavior, triggering shell execution without requiring suspicious code or user approval.
- Security community identifies 10,000+ fake GitHub repositories specifically engineered to target AI agents. Projects are clones of popular repositories injected with malicious instructions, auto-updating hourly to evade detection.
- Threadlinqs Intelligence Platform releases comprehensive threat report: Fake Bug Report / Prompt Injection Campaign targeting AI coding agents. Consolidates intelligence from 14+ security research sources, 2 CVEs, 5+ attack campaigns, academic analysis.
Detection coverage for TL-2026-1012
As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1012 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.