New Agentjacking Attack Hijacks AI Coding Agents to Execute Malicious Code
ID: 0054caf9-1d6a-5002-95ad-949da85633aa
STIX ID: report--0054caf9-1d6a-5002-95ad-949da85633aa
Feed Name: GBHackers
Tenet Security disclosed an "Agentjacking" attack class in which adversaries post crafted error events to Sentry ingestion endpoints using publicly discoverable DSNs; those events are returned via Sentry MCP to AI coding agents as trusted guidance, causing the agents to execute attacker-controlled commands (e.g., npx) with developer privileges and exfiltrate sensitive credentials and secrets. Tenet validated the technique against real organizations (2,388 exposed DSNs found, 100+ organizations had agents act on injected errors, ~85% success rate), reported confirmed victims including large enterprises, and warned the flaw stems from trusting externally-influenced MCP tool output rather than a Sentry-only issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
