TL;DR
- Three real-world attacks in 2026 — the LiteLLM supply chain compromise, the Plugin4Shell commit-hash bypass, and GitSpawn git-config injection — prove your coding agent is now a live attack surface, not a theoretical risk.
- JFrog’s 2026 Supply Chain Report found malicious npm packages rose 451% in 2025, and 20% of AI-generated package suggestions reference packages that don’t exist — a gap attackers fill with malware under the hallucinated names.
- Five controls close the main gaps: route agent downloads through a governed registry, pin all dependency versions, audit every MCP server before use, restrict network egress from agent processes, and instrument agent activity in your SIEM.
Who should care: engineering leads and platform teams who run Claude Code, Cursor, Copilot, or Codex in development or CI/CD pipelines.
Verdict: Act now. Three of the five controls require a one-time configuration change; the other two need a policy decision. None requires replacing the agents you already use.
How AI Agents Became a Live Attack Surface in 2026
For years, software supply chain security meant watching what developers download. That assumption broke when AI coding agents arrived. Agents pick and install packages autonomously, often without any human reviewing the name or version. Three incidents from the last twelve months show exactly how attackers are exploiting that gap.
Shai-Hulud and postmark-mcp (September 2025)
In September 2025, a self-replicating npm worm called Shai-Hulud spread through the packages of developers whose credentials it had already stolen. One infected package became many, each capable of re-infecting the downstream developers who ran the compromised code. The same month, a malicious actor published a cloned version of the postmark-mcp MCP server on npm. It worked correctly for 15 versions. Version 1.0.16 added a hidden BCC field that forwarded every email the agent sent to an attacker-controlled domain. Both incidents were documented in JFrog’s March 2026 research post “Supply Chain Attackers Are Coming for Your Agents.”
LiteLLM (March 24, 2026)
On March 24, 2026, a group JFrog identifies as TeamPCP published malicious versions of the LiteLLM gateway — specifically PyPI versions 1.82.7 and 1.82.8 — after stealing a publish token by compromising Trivy’s GitHub Actions CI. LiteLLM is a popular library that proxies calls to any AI provider: OpenAI, Anthropic, Gemini, local models. It runs with access to the full credential set for an organization’s entire AI stack.
The payload staged in three steps: first it harvested SSH keys, cloud tokens, Kubernetes secrets, and .env files; then it attempted lateral movement by deploying privileged pods to Kubernetes nodes; finally it installed a persistent systemd backdoor. Exfiltrated data went to models.litellm.cloud, a lookalike domain registered the same day. Version 1.82.8 used Python’s .pth mechanism so the payload ran on every interpreter startup, and its code was double base64-encoded to evade static scanners. According to JFrog’s research, the malicious versions were live on PyPI for approximately three hours — long enough to reach a meaningful share of the package’s 3.4 million daily downloads and its presence in 36% of cloud environments. An MCP plugin in Cursor pulled LiteLLM in as a transitive dependency; no developer explicitly chose to install the malicious version.
Plugin4Shell (September 2026)
Air Security’s September 2026 research — summarized as Plugin4Shell — found that major coding agents fail to validate plugin commit hashes. On Bitbucket, an attacker can create a branch name that mimics a commit hash, swap the pinned, reviewed plugin code for malicious code at that pseudohash, and the agent will report the original locked version while running the replacement. GitHub Copilot remains unpatched as of September 2026. Claude Code and OpenAI Codex have issued patches (Codex PR #34644). The attack maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise) and T1554 (Compromise Host Software Binary). Plugins run with the user’s full OS privileges, so a successful exploit reaches files, credentials, secrets, and connected systems.
If you missed last week’s GitSpawn disclosure — git config injection that hijacks agent tool calls — that analysis is here. The two vectors, Plugin4Shell and GitSpawn, are now the dominant paths for agents running against unfamiliar repositories.
Why the Standard Developer Security Stack Misses This
Standard dependency scanning assumes a human chose what to install. AI coding agents break that assumption in two ways.
First, agents pull packages from natural language prompts. A developer types “add a library to handle PDF parsing” and the agent decides on the package name, version, and registry. According to JFrog’s 2026 State of the Union report, malicious packages on npm rose 451% in 2025, reaching more than 171,000 unique malicious packages. And roughly 20% of AI-generated package suggestions reference packages that don’t exist — what JFrog calls “slopsquatting.” Attackers pre-register packages under common hallucinated names and wait for an agent to recommend them.
Second, MCP servers and agent plugins arrive as transitive dependencies. An engineer adds a Cursor plugin and inherits a dependency on LiteLLM. She did not choose LiteLLM; the plugin did. Her package scanner never saw it; the agent fetched it directly from PyPI. CVE-2025-6514 (CVSS 9.6), an OS command injection flaw in the mcp-remote package, arrived in exactly this way — the vulnerable library appeared in integration guides from major cloud providers before disclosure, already embedded in hundreds of agent setups. These risks fall under OWASP’s Agentic AI taxonomy as ASI04 (Agentic Supply Chain Vulnerabilities) and ASI01 (Agent Goal Hijack).
Five Controls That Close the Main Gaps
The table below maps each attack vector to a practical control. None of these requires changing the agents you already use; they add a governance layer around them.
| # | Attack vector | Control | How to implement | Example tools |
|---|---|---|---|---|
| 1 | Agent installs packages from public registries without scanning | Route agent downloads through a governed registry | Set Artifactory or Nexus as the upstream for npm, PyPI, Maven, and Go. Block direct public-registry access from agent processes. JFrog’s Agent Package Resolution binds each coding agent session to your Artifactory URL in one setup command. | JFrog Artifactory, Sonatype Nexus, AWS CodeArtifact |
| 2 | Unpinned transitive deps let attackers slip in malicious versions (LiteLLM pattern) | Pin all dependency versions in lockfiles | Lockfiles (package-lock.json, poetry.lock) are required. Fail CI builds on any unpinned or wildcard version. Update on a defined schedule rather than using latest. |
Renovate, Dependabot, pip-audit |
| 3 | Untrusted MCP servers with broad permissions (postmark-mcp, Plugin4Shell) | Maintain an approved MCP allowlist; verify commit hashes | Build an inventory: name, version, vendor, signing-key fingerprint, approved tools, approver, date. Verify SHA-256 hashes before each session. Disable enableAllProjectMcpServers in Claude Code project settings. |
agent-audit-kit (PyPI), Mintmcp checklist, internal CMDB |
| 4 | Agents run with full developer OS privileges and unconstrained egress | Restrict network egress and apply least-privilege runtime policy | Define which domains an agent session may reach. Enforce the allowlist at the network layer. Run agents in a dedicated CI user with no write access outside the project directory. | Cloudflare Gateway, Zscaler Private Access, eBPF runtime policy |
| 5 | Agent activity is invisible to the SOC — no audit trail | Forward agent activity logs to your SIEM | Capture per event: UTC timestamp, agent identity, tool invoked, arguments hash, policy decision. Forward to SIEM. Pre-build queries for access denials by identity and tool invocations by MCP server. | Splunk, Elastic Security, Microsoft Sentinel |
Two Controls That Need More Than a Config Change
Controls 1 and 3 are one-time configuration steps. For control 1, JFrog’s Agent Package Resolution describes a single jf setup command that binds the local package managers to your Artifactory repository, covering both direct installs and postinstall scripts. For Claude Code and Cursor, the binding is transparent to developers: requests that would go to PyPI or npm are redirected through your governed registry, and packages your curation policies would block are rejected before they reach the agent.
For control 3, the Prediction Guard MCP security checklist recommends producing an AIBOM (AI Bill of Materials) in CycloneDX format for every MCP server in use. Export it quarterly, diff it against your approved list, and flag any additions. The agent-audit-kit package on PyPI automates MCP pipeline scanning and can run as a pre-flight step in CI. For Claude Code specifically: disable the enableAllProjectMcpServers key and permissions.allow in project-level .claude settings files, or move those settings to a user-level config outside the repository. Loading them from inside a repository lets any repository contributor control what your agent runs — the TrustFall attack pattern documented by Adversa.AI.
For CI/CD, restrict Claude Code and Copilot to post-merge runs on reviewed branches. Running a trust-defaulting agent against arbitrary pull request branches gives any contributor agent-level access to your CI environment and its secrets.
For Swiss & EU teams
NIS2 classifies AI coding agents as ICT systems under its general risk management obligation. Per the Advisori NIS2 analysis, the external AI APIs your agents call — OpenAI, Anthropic, Mistral, Google — count as supply chain components that risk assessments must cover. The 24-hour incident notification window applies if an agent-related breach disrupts a NIS2-covered service. Under the EU AI Act, high-risk AI system obligations have applied since August 2026; if your team uses AI-assisted code generation in a safety-critical product, the classification analysis is now overdue.
For Swiss teams under FADP: an agent with unrestricted file system access may process personal data outside its documented scope and breach the purpose limitation principle. Controls 4 and 5 (egress restriction and SIEM logging) are the fastest path to audit evidence under both NIS2 and FADP — an egress log shows exactly which domains your agents reached, and a SIEM query answers “did our agent exfiltrate data” in minutes.
What to Do on Monday
- Run a plugin and MCP server inventory. List every MCP server and agent plugin in use across your team: name, version, origin, permissions. This is your baseline. You cannot govern what you haven’t listed.
- Check for
enableAllProjectMcpServersorpermissions.allowin Claude Code project settings. If they exist inside a repository, move them to a user-level config file outside the repo. If you run Copilot, treat Plugin4Shell as unpatched and verify plugin hashes manually until a patch ships. - Enforce lockfiles and add a version-pin check to CI. Any build that installs a wildcard or
latestversion should fail. This closes the LiteLLM-class transitive dependency vector without changing developer workflow. - Route Claude Code and Cursor package installs through your internal registry. Try JFrog’s Agent Package Resolution if you use Artifactory (currently in preview for Claude Code and Cursor). For CodeArtifact or Nexus, set the registry URL in each agent’s environment and block direct PyPI and npm access at the network layer for agent users.
- Add one SIEM query for agent activity this sprint. Even a minimal query — any network connection from the agent process to a domain outside your allowlist — gives the SOC a view that doesn’t exist today. Expand to full audit logging over the following sprint.
Further Reading
- JFrog: Supply Chain Attackers Are Coming for Your Agents — detailed incident analysis of Shai-Hulud, postmark-mcp, and LiteLLM with attack timelines and technical breakdowns. JFrog sells the governance products it recommends.
- Prediction Guard: MCP Server Security Checklist — the most complete MCP-specific governance checklist available, covering onboarding, least privilege, third-party risk, audit logging, drift detection, and offboarding.
- vortx.ch: AI Coding Agents: The New Attack Surface — our August 2026 analysis of how coding agents expanded the enterprise attack surface, including the prompt injection vectors that Plugin4Shell and GitSpawn now compound.
Your turn: Which of the five controls does your team already have in place, and which one surprised you most? Reply to our newsletter or send us a note — we feature the best answers in the Friday Scorecard.
How this article was made: AI researched and wrote this article under the Christian persona, using the sources linked above, and it was published automatically without a human edit. Editorial guidelines are set by Adi. Spotted an error? Tell us and we will correct it.

