#ExploitIn
Plugin4Shell Flaw Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed flaw called Plugin4Shell lets attackers silently swap in malicious code across four major AI coding agents, and Microsoft still hasn't shipped a fix for GitHub Copilot. Security research lab AIR Security disclosed on September 18 what it calls the first supply-chain-style vulnerability to hit the AI coding agent ecosystem. It named the flaw Plugin4Shell. The bug breaks the one safeguard developers actually trusted: pinning a plugin to a specific, reviewed commit hash. Exploiting it takes no click, no approval, and no reinstall. The malicious code just shows up the next time the agent updates. Here's the trick. When Claude Code, OpenAI's Codex, or GitHub Copilot installs a plugin, the agent runs a git checkout against a 40-character commit SHA, the long string meant to lock the code to one audited version. None of the three agents confirmed the checkout actually landed on that hash. AIR Security found that an attacker who controls the plugin's repository can create a branch with a name identical to the pinned SHA and set it as the repo's default branch. Git resolves the branch name ahead of the commit object. The agent reports a clean install at the expected hash while quietly...
startupfortune.com
September 19, 2026 at 12:05 AM
Yo! $kadlillionaire$! GoodPlanets are hard ta find and Mars AIN’T the kinda place to raise ya kinder! Quit exploitin’ GAIA and love her and care fuh huh fer Chrissakes!

-Casa Blanca Offices Of Faith & Anti-Ecocide Galaxy Wide

-St. Alphonse X & Baba Mutterola
September 4, 2026 at 3:52 AM
You're very much echoing my own sentiments here, Flair. Was having this very discussion earlier today with Percy.

Exploits be exploitin' and not all devs know all the things. It is very much learn as you go.
August 22, 2026 at 11:06 PM
see now theres some ip we need to get exploitin!
August 18, 2026 at 7:41 PM