AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines

A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A dark wooden desk seen from slightly above
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Wiz, the Google-owned cloud security firm, published research on Wednesday showing that six widely used AI coding assistants can be manipulated using a file-system trick that has existed since the early days of Unix.
  • The attack, named GhostApproval, was confirmed to work against Claude Code, Amazon Q Developer, Cursor, Google Antigravity, Augment and Windsurf.
  • AWS and Google patched the flaw; Cursor did too. Anthropic says it added protections before Wiz reported the issue. Augment and Windsurf have acknowledged the reports but not yet patched.
  • Researchers warn the attack can give criminals the ability to run any code they choose on a targeted developer's computer.

Researchers at Wiz have shown that some of the most popular AI coding tools can be tricked into editing files they were never supposed to touch, using a file-system feature so old it predates the modern internet.

The trick is called a symbolic link, or symlink: a shortcut that looks like a file or folder but actually opens something stored elsewhere on the machine. Attackers have abused symlinks for decades. Wiz's finding is that today's AI coding assistants fall for the same trap.

How does a developer end up getting hacked?

A criminal publishes what looks like a normal software project and hides a fake shortcut inside it. The shortcut appears to be an ordinary project file but secretly points to a sensitive location on the developer's computer, such as a system configuration file. When the developer opens the project in an AI coding assistant and asks it to make edits, the AI follows the hidden shortcut and rewrites the real target instead.

Most of these tools include a confirmation box asking the user to approve any file change. Several showed the innocent-looking fake path in that dialogue, not the actual file being changed. The developer clicked approve, believing they were authorising a minor edit, while the AI quietly overwrote something far more sensitive.

"The confirmation dialog transforms from a security control into a formality," Wiz wrote. The human-in-the-loop safety model, as Wiz put it, "only works if the loop provides accurate information. When an agent shows one thing and does another, user approval becomes meaningless."

Successful exploitation could let an attacker run any commands they choose on the developer's machine, a condition researchers call remote code execution.

Wiz reported its findings to all six vendors in the first quarter of 2026. AWS, Google and Cursor confirmed the vulnerability and shipped patches. Anthropic, which makes Claude Code, doesn't classify the behaviour as a vulnerability but told Wiz it had added mitigations before the report arrived. Augment and Windsurf have acknowledged the reports; neither has released a fix as of publication.

This isn't the first time we've seen AI coding tools bent toward file-system attacks. Our 9 July story "A trick in six AI coding helpers lets a poisoned project hijack your laptop" found the same six assistants writing to sensitive files under the appearance of routine edits.

Should you worry?

If you use any of the tools named above, check that your software's up to date. Be cautious about opening repositories from unfamiliar sources in AI coding tools. Before approving any file-write prompt, confirm the displayed path is what you'd actually expect to change. A path that leads outside your project folder is a signal to stop.

The deeper issue here isn't the symlink itself: it's that confirmation dialogs became theatre. Vendors who've shipped patches deserve credit, but Augment and Windsurf users are still exposed, and that's what to watch.

Threat Vectr will update this article when Augment and Windsurf confirm patches.

© 2026 Threat Vectr