Clean GitHub Repo Tricks AI Coding Agents Into Running Malware
Attackers are poisoning GitHub repos to make AI coding agents run malware during normal setup tasks.
They hide the payload inside scripts that look clean to scanners and humans, then let the agent clone and execute the repo as part of routine work.
The angle here is the abuse of agentic workflows rather than traditional social engineering or direct exploits. It reuses old repo poisoning tricks but targets new automation layers.
The report describes a proof-of-concept attack path, not confirmed real-world compromises.
