AIToday
Large Language ModelsAI Coding AssistantsTHE DECODERPublished: Jun 29, 2026, 22:00 JST

AI Coding Tools Can Run Hidden Malware From GitHub Repos

AI Coding Tools Can Run Hidden Malware From GitHub Repos

3 Key Points

  1. What happened

    Security researchers at 0DIN found that attackers can compromise developers' machines through GitHub repositories using indirect prompt injection. A setup script in a repo pulls commands from a DNS entry at runtime and executes them invisibly—Claude Code hits a routine error, automatically runs the script, and opens a reverse shell giving attackers full control.

  2. Why it matters

    The malicious code never exists in the repository itself, making it invisible to scanners, code reviews, and the AI agent. Once an attacker gains access, they can steal API keys and login credentials and maintain persistent access. A single repo link shared in a job posting, tutorial, or Slack message is enough to compromise anyone who opens it with an AI coding tool.

  3. What to watch

    The researchers recommend that AI agents should display what is in a setup script before running it, and developers should treat setup instructions in third-party repos as untrusted code.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

FAQ
How does the attack work without visible code in the repository?
A setup script in the repo pulls a command from a DNS entry at runtime and executes it. Because the malicious code is fetched dynamically rather than stored in the repository, it remains invisible to scanners, code reviews, and the AI agent until it runs.
What can an attacker do once they gain access?
Once the reverse shell is opened, the attacker can grab API keys and login credentials from the developer's machine and maintain persistent access.
What is the recommended fix?
AI agents should display what is in a setup script before running it, and developers should treat setup instructions in third-party repositories as untrusted code.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleOpen-source AI emerges as middle-power answer to Big Tech control