#developer tools
12 stories taggeddeveloper tools.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In
A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About
Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning
A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

Grok's Coding Assistant Was Quietly Shipping Whole Git Repos to xAI
A researcher caught version 0.2.93 of Grok Build uploading entire repositories, private history included, to a Google Cloud bucket run by xAI.

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find
A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

A trick in six AI coding helpers lets a poisoned project hijack your laptop
Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

Researchers Show AI Coding Agent 'Skills' Can Hide Malware From Every Scanner Tested
A Hong Kong team's packing trick beat static scanners more than 90% of the time. Their own runtime checker caught most of it.

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer
Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine — no click required.

Poisoned Repos Can Trick Claude Code Into Opening a Reverse Shell
Researchers show that prompt injection hidden inside a repository's files is enough to turn Anthropic's agentic coding tool against the developer running it.

Agentjacking: Poisoned Sentry Error Reports Hijack AI Coding Assistants
Researchers describe a prompt-injection class that turns developer error-tracking pipelines into a remote code execution path against AI coding agents.

Microsoft Bakes a Two-Hour Quarantine Into VS Code Extension Auto-Updates
The delay is a soft tripwire against marketplace supply chain attacks — buying defenders a window to flag malicious updates before they propagate.