logo

New Agentjacking Attack Hijacks AI Coding Agents to Execute Malicious Code

ID: 0054caf9-1d6a-5002-95ad-949da85633aa

STIX ID: report--0054caf9-1d6a-5002-95ad-949da85633aa

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

Author: Eswar

...
...

Tenet Security disclosed an "Agentjacking" attack class in which adversaries post crafted error events to Sentry ingestion endpoints using publicly discoverable DSNs; those events are returned via Sentry MCP to AI coding agents as trusted guidance, causing the agents to execute attacker-controlled commands (e.g., npx) with developer privileges and exfiltrate sensitive credentials and secrets. Tenet validated the technique against real organizations (2,388 exposed DSNs found, 100+ organizations had agents act on injected errors, ~85% success rate), reported confirmed victims including large enterprises, and warned the flaw stems from trusting externally-influenced MCP tool output rather than a Sentry-only issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.