Updated
Updated · InfoWorld · Sep 18
Plugin4Shell Hits 4 AI Coding Agents, Enabling Zero-Click Code Execution
Updated
Updated · InfoWorld · Sep 18

Plugin4Shell Hits 4 AI Coding Agents, Enabling Zero-Click Code Execution

3 articles · Updated · InfoWorld · Sep 18

Summary

  • AIR researchers found Plugin4Shell, a zero-click remote-code-execution flaw that lets attackers replace a trusted plugin with a malicious one in Codex, Claude Code, Gemini CLI and GitHub Copilot.
  • The bug stems from agents passing a reviewed Git commit SHA to Git but not verifying the code actually checked out, allowing a repository owner or hijacker to make malicious code appear as the approved version.
  • Anthropic patched Claude Code in version 2.1.179 and OpenAI fixed Codex in 0.146.0; Google said Gemini CLI is deprecated and urged users to move to Antigravity, while researchers said GitHub Copilot still lacks a full fix.
  • Enterprise exposure could be broad because plugins often inherit developer access to source code, credentials, cloud systems and CI/CD tools, creating paths to steal keys, alter repositories or pivot deeper into corporate networks.
  • The flaw was discovered in May and disclosed in June, and researchers said updating agents is essential because marketplace controls alone cannot fully prevent attacks across repositories hosted beyond GitHub.

Insights

If cryptographic hashes fail to guarantee AI plugin safety, how can organizations defend against zero-click supply chain attacks?
Could your trusted AI coding assistant be silently handing over your enterprise's crown jewels to hackers right now?