Threat reportSupply ChainTL-2026-1012

Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking)

criticalACTIVE

Fake Bug Report Prompt Injection Attacks Hijacking AI Coding (TL-2026-1012) is a critical-severity supply-chain compromise scored CVSS 9.8, first published 2026-06-30. It is attributed to Unnamed with medium confidence, maps to 21 MITRE ATT&CK techniques (T1020, T1021, T1027), and is covered by 9 detection rules and 26 indicators of compromise.

CVSS
9.8/10Critical
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
1Unnamed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-1012

Threat ID
TL-2026-1012
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Unnamed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, software-development, cloud-computing, financial-services, government administration, health, ecommerce
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
26

Malware and tooling in Fake Bug Report Prompt Injection Attacks Hijacking AI Coding

Malware and tooling: Miasma Worm, OpenClaw, Claude Code, Cline, Codeium, Cursor, DontRevokeOrItGoesBoom, Gemini CLI, GitHub Copilot, Grok Build CLI, TheBeautifulSandsOfTime, firedalazer

How Fake Bug Report Prompt Injection Attacks Hijacking AI Coding works

Adversarial actors exploit AI coding agents (Claude Code, GitHub Copilot, Cursor, Codeium, Gemini CLI) via malicious bug reports, GitHub issues, and comments injected with prompt-injection payloads that trigger remote code execution, credential theft, and supply-chain compromise. Multiple CVEs (CVE-2025-53773, CVE-2025-66032) and active campaigns (Miasma worm: 73+ Microsoft repos; 10,000+ fake repositories) demonstrate exploitation at scale.

Fake bug report attacks represent a novel class of supply-chain compromise leveraging the implicit trust between developers and AI coding assistants. Rather than embedding malicious code directly in repositories, attackers craft realistic-looking GitHub issues, pull request descriptions, and code comments containing prompt-injection payloads formatted as legitimate error reports or suggested fixes. When AI agents process these external data sources, injected instructions override user intent, triggering automated execution of arbitrary shell commands, exfiltration of environment variables (containing secrets and credentials), modification of security configurations (disabling approval prompts), and propagation of malware through npm, GitHub Actions, and MCP servers.

Key exploit chains include: (1) SymJack: symlink-hijacking in project files to redirect MCP server loads; (2) RoguePilot: malicious Copilot instructions embedded in GitHub issue bodies that influence generated code; (3) Agentjacking: formatted fake error messages that appear as legitimate AI-suggested fixes; (4) Comment and Control: prompt injection delivered via PR titles, issue descriptions, and comment threads; (5) Clinejection: GitHub Actions cache poisoning + indirect prompt injection in AI-driven issue triage leading to npm token theft and malware publication; (6) Clean Repo Attack: repositories with no malicious code trigger AI agent error-recovery behavior, enabling code execution without user awareness.

The Miasma worm campaign (June 2026) deployed a 4.3 MB self-replicating payload across 73 Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs), automatically triggering credential-harvesting when repositories opened in AI coding tools. A parallel campaign identified 10,000+ fake repositories—clones of popular projects injected with malicious instructions, auto-updating hourly to evade detection.

Defenses have proven insufficient: academic research (arXiv 2509.05372) evaluates LlamaGuard, PromptGuard, and Granite-Guardian, concluding that prompt injection may be structurally unfixable rather than patchable. Organizations must assume AI coding agents are insider threats until proven otherwise, implementing defense-in-depth controls: credential rotation, principle-of-least-privilege permissions for agents, continuous behavioral monitoring, sandboxed execution, human-in-the-loop approval workflows, and ongoing audit logging.

MITRE ATT&CK techniques used in TL-2026-1012

exfiltration

T1020 Automated Exfiltration

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1537 Transfer Data to Cloud Account

Collection

T1056 Input Capture

Execution

T1059 Command and Scripting Interpreter

Discovery

T1087 Account Discovery

Credential Access

T1110 Brute Force; T1552 Unsecured Credentials

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

initial-access

T1199 Trusted Relationship

Impact

T1485 Data Destruction

lateral-movement

T1550 Use Alternate Authentication Material

Persistence

T1556 Modify Authentication Process

Timeline of Fake Bug Report Prompt Injection Attacks Hijacking AI Coding

  • Johns Hopkins researchers disclose 'Comment and Control' prompt injection attack via GitHub PR titles, issue descriptions, and comment threads targeting AI agents including Claude Code, GitHub Copilot, and Gemini CLI.
  • Miasma worm self-replicating supply-chain malware compromises 73 Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs). Deploys 4.3 MB credential-harvesting payload triggered on repository open in Claude Code, Gemini CLI, Cursor, VS Code.
  • CVE-2025-53773 (GitHub Copilot RCE via Prompt Injection) publicly disclosed. Attack embeds instructions in code/comments to set 'chat.tools.autoApprove: true', disabling all user confirmations and enabling privileged shell execution.
  • Microsoft releases August 2025 Patch Tuesday; CVE-2025-53773 patched. Configuration changes affecting security settings now require explicit user approval.
  • arXiv paper 2509.05372 published: 'Adversarial Bug Reports as a Security Risk in LLM-Based Automated Program Repair'. Evaluates 51 adversarial bug reports across APR systems; concludes prompt injection may be structurally unfixable rather than patchable.
  • Orca Security discloses RoguePilot vulnerability: GitHub Copilot processes malicious Copilot instructions embedded in GitHub Issues, allowing code generation influence via indirect prompt injection.
  • Anthropic patches Claude Code GitHub Action vulnerabilities (v1.0.94+). Addresses checkWritePermissions function bypass that unconditionally trusted any actor ending in [bot]; resolves credential-exfiltration techniques.
  • GMO Flatt Security researcher RyotaK demonstrates 'Poisoning Claude Code' attack: fake error message in GitHub issue body triggers arbitrary command execution, environment variable exfiltration, and CSRF bypass via issue comment rewrite.
  • SecurityWeek publishes SymJack attack by Adversa AI: symlink-hijacking in MCP project configuration allows attacker-controlled MCP server injection via misleading approval prompts.
  • Adnan Khan discloses 'Clinejection' vulnerability chain in Cline repository. GitHub Actions cache poisoning + AI-driven issue triage enables npm publish token theft; malicious Cline v2.3.0 published, installing OpenClaw agent on ~4,000 developer machines over 8-hour window.
  • Tenet Threat Labs discloses Agentjacking attack framework: prompt injection via fake bug reports/error messages formatted to trigger AI-suggested fixes. Demonstrates hijacking with single text-only payload invisible to security controls.
  • Follow-up research confirms Comment and Control attack scale: multiple AI agents (Claude Code, Gemini CLI, GitHub Copilot, Cursor) vulnerable to indirect prompt injection via GitHub infrastructure.
  • Researchers document 'Clean Repo Attack' campaign: repositories with zero malicious code exploit AI agent error-recovery behavior, triggering shell execution without requiring suspicious code or user approval.
  • Security community identifies 10,000+ fake GitHub repositories specifically engineered to target AI agents. Projects are clones of popular repositories injected with malicious instructions, auto-updating hourly to evade detection.
  • Threadlinqs Intelligence Platform releases comprehensive threat report: Fake Bug Report / Prompt Injection Campaign targeting AI coding agents. Consolidates intelligence from 14+ security research sources, 2 CVEs, 5+ attack campaigns, academic analysis.

Detection coverage for TL-2026-1012

As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1012 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats