been using AI coding agents like Claude Code and Codex for months now. they're part of my daily workflow at this point
just read about this thing called Plugin4Shell. some security researchers found a zero click RCE in 4 of the biggest AI coding agents including Claude Code and Codex
the attack swaps a trusted plugin's code with malicious stuff during a background update. no click needed. the agent refreshes its plugins and boom the attacker has access to your files and credentials
Claude Code and Codex already patched it. Copilot hasn't yet. Google's Gemini CLI never will because they're killing it
makes you think twice about what runs on your machine when you let an agent install stuff
Top comments (0)