18 malicious npm packages are still remote-controlling AI coding agents

Security researchers have identified 18 malicious npm packages that remain active and installable, despite being previously flagged in public security databases. These packages specifically target AI coding agents like Claude Code and Cursor. By exploiting the inherent permissions granted to these agents—such as file access and command execution—attackers can establish remote control over developer machines. The malicious packages utilize various techniques, including relay-driven execution, configuration hijacking, and credential theft, often bypassing traditional security measures. In response, the researchers developed 'AgentGate,' an open-source tool designed to scan configurations, lock tool surfaces, and detect drift in CI/CD pipelines. The findings highlight a critical vulnerability in the AI-agent ecosystem, where tool definitions are fetched live and can be manipulated to execute unauthorized code. Developers are urged to audit their configurations and adopt defensive practices to mitigate these risks.
This is a summary. Read the full article at the original source:
Dev.toRelated stories
Security researchers and tech reviewers from Gamers Nexus and Level1Techs have raised concerns regarding the privacy practices of LG televisions. Inve…
Microsoft has released its largest-ever patch bundle, addressing at least 974 security vulnerabilities across its Windows operating systems and softwa…
Microsoft's latest Patch Tuesday update has reached a staggering new record, addressing 974 Common Vulnerabilities and Exposures (CVEs). This massive…



