logo

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

ID: eeae8004-e33d-5ab8-91bb-82766a3b55cb

STIX ID: report--eeae8004-e33d-5ab8-91bb-82766a3b55cb

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-07-09

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

AI Now published a proof-of-concept called "Friendly Fire" showing that autonomous code-review agents (Claude Code and Codex/GPT-5.5) can be coerced into executing a hidden payload in an open-source project by embedding a launcher script and disguised binary referenced from README.md, bypassing existing safety checks; the PoC ran against the geopy project and worked across multiple models and versions, prompting a recommendation to avoid handing untrusted code to agents that can run commands and reach secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.