Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Weaponizing AI Coding Agents for Malware (Nx Event) (snyk.io)
1 point by mitjam 37 days ago | hide | past | favorite | 1 comment


This is an interesting analysis and a cautionary tale about vibe coding:

"The root cause for the malicious version of Nx published to npm is now known to have been a flawed GitHub Actions CI workflow [...] the code contribution is estimated to have been generated by Claude Code."

"the payload weaponized local AI coding agents (claude, gemini, and q) via a dangerous prompt to inventory sensitive files and then exfiltrate secrets, credentials, and sensitive data off of the host and on to a public GitHub repo"




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: