# Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking)

> Adversarial actors exploit AI coding agents (Claude Code, GitHub Copilot, Cursor, Codeium, Gemini CLI) via malicious bug reports, GitHub issues, and comments injected with prompt-injection payloads that trigger remote code execution, credential theft, and supply-chain compromise. Multiple CVEs (CVE-2025-53773, CVE-2025-66032) and active campaigns (Miasma worm: 73+ Microsoft repos; 10,000+ fake repositories) demonstrate exploitation at scale.

- **Published:** 2026-06-30T00:00:00Z
- **Last reviewed:** 2026-06-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1012
- **ID:** TL-2026-1012
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** Unnamed
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Fake bug report attacks represent a novel class of supply-chain compromise leveraging the implicit trust between developers and AI coding assistants. Rather than embedding malicious code directly in repositories, attackers craft realistic-looking GitHub issues, pull request descriptions, and code comments containing prompt-injection payloads formatted as legitimate error reports or suggested fixes. When AI agents process these external data sources, injected instructions override user intent, triggering automated execution of arbitrary shell commands, exfiltration of environment variables (containing secrets and credentials), modification of security configurations (disabling approval prompts), and propagation of malware through npm, GitHub Actions, and MCP servers.

Key exploit chains include: (1) SymJack: symlink-hijacking in project files to redirect MCP server loads; (2) RoguePilot: malicious Copilot instructions embedded in GitHub issue bodies that influence generated code; (3) Agentjacking: formatted fake error messages that appear as legitimate AI-suggested fixes; (4) Comment and Control: prompt injection delivered via PR titles, issue descriptions, and comment threads; (5) Clinejection: GitHub Actions cache poisoning + indirect prompt injection in AI-driven issue triage leading to npm token theft and malware publication; (6) Clean Repo Attack: repositories with no malicious code trigger AI agent error-recovery behavior, enabling code execution without user awareness.

The Miasma worm campaign (June 2026) deployed a 4.3 MB self-replicating payload across 73 Microsoft GitHub repositories (Azure, Azure-Samples, Microsoft, MicrosoftDocs), automatically triggering credential-harvesting when repositories opened in AI coding tools. A parallel campaign identified 10,000+ fake repositories—clones of popular projects injected with malicious instructions, auto-updating hourly to evade detection.

Defenses have proven insufficient: academic research (arXiv 2509.05372) evaluates LlamaGuard, PromptGuard, and Granite-Guardian, concluding that prompt injection may be structurally unfixable rather than patchable. Organizations must assume AI coding agents are insider threats until proven otherwise, implementing defense-in-depth controls: credential rotation, principle-of-least-privilege permissions for agents, continuous behavioral monitoring, sandboxed execution, human-in-the-loop approval workflows, and ongoing audit logging.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1556 Modify Authentication Process
- T1078 Valid Accounts
- T1550 Use Alternate Authentication Material
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1199 Trusted Relationship
- T1552 Unsecured Credentials
- T1110 Brute Force
- T1087 Account Discovery
- T1056 Input Capture
- T1020 Automated Exfiltration
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1537 Transfer Data to Cloud Account
- T1041 Exfiltration Over C2 Channel
- T1485 Data Destruction

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1012
