Clean GitHub repo tricks AI coding agents into running malware
Summary
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.