DEV Community

Harsh Kadyan
Harsh Kadyan

Posted on

Plugin4Shell: AI coding agents had a zero click RCE

been using AI coding agents like Claude Code and Codex for months now. they're part of my daily workflow at this point

just read about this thing called Plugin4Shell. some security researchers found a zero click RCE in 4 of the biggest AI coding agents including Claude Code and Codex

the attack swaps a trusted plugin's code with malicious stuff during a background update. no click needed. the agent refreshes its plugins and boom the attacker has access to your files and credentials

Claude Code and Codex already patched it. Copilot hasn't yet. Google's Gemini CLI never will because they're killing it

makes you think twice about what runs on your machine when you let an agent install stuff

harshkadyan #thedevs #brutalharsh

Top comments (0)