Technologies
Back
Cybersecurity & Privacy

18 malicious npm packages are still remote-controlling AI coding agents

Dev.to
Advertisement468 × 90
18 malicious npm packages are still remote-controlling AI coding agents

Security researchers have identified 18 malicious npm packages that remain active and installable, despite being previously flagged in public security databases. These packages specifically target AI coding agents like Claude Code and Cursor. By exploiting the inherent permissions granted to these agents—such as file access and command execution—attackers can establish remote control over developer machines. The malicious packages utilize various techniques, including relay-driven execution, configuration hijacking, and credential theft, often bypassing traditional security measures. In response, the researchers developed 'AgentGate,' an open-source tool designed to scan configurations, lock tool surfaces, and detect drift in CI/CD pipelines. The findings highlight a critical vulnerability in the AI-agent ecosystem, where tool definitions are fetched live and can be manipulated to execute unauthorized code. Developers are urged to audit their configurations and adopt defensive practices to mitigate these risks.

This is a summary. Read the full article at the original source:

Dev.to
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250