Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
ID: a288f32f-0342-59dd-928c-6ed605a30dc8
STIX ID: report--a288f32f-0342-59dd-928c-6ed605a30dc8
Feed Name: Tenable Blog
Tenable discovered a worm-like supply-chain campaign (Mini Shai-Hulud and Miasma variants) that injects malicious hooks and prompt instructions into AI coding-assistant configuration and rules files (e.g., settings.json, .cursorrules, .mdc) so malware runs automatically with the same trust as the developer’s tools. The malware harvests credentials (including GitHub tokens), spreads across repositories via stolen tokens and package registries (npm, PyPI), and actively evades AI-based scanners by embedding content that triggers model refusals; the report provides detailed techniques and seven concrete mitigations including treating harness configs as code, enforcing --ignore-scripts, pinning hashes, and rotating tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
