Tuesday Sep 22

One Git Trick Hit Four Coding Agents

22SEP
2 PATCHED, 2 NOT1 PLUGIN4 AGENTS

One bug gives attackers remote code execution across the four big coding assistants. No click needed. Half the vendors fixed it within weeks. The other half shrugged, and one of them is Microsoft.

Plugins are pinned to a commit SHA for safety. AIR Security found that a branch named as that SHA wins the fetch. Auto-update pulls it with no click.

Anthropic patched Claude Code 2.1.179. OpenAI patched Codex 0.146.0. Google is deprecating Gemini CLI and will not fix it. Microsoft has not responded, and Copilot is in 90 percent of the Fortune 500.

GitHub blocks SHA-shaped branch names, but Bitbucket-hosted marketplaces do not. AIR calls it the first AI supply-chain attack of its kind.

full brief & sources

⚡ Why this matters

  • Four agents, one shared assumption, one bug. Coding agents copy each other's plugin architecture, so they share each other's holes.
  • Auto-update turns a supply-chain bug into zero-click RCE on developer machines with production credentials.
  • Deprecation as a patch strategy is new. Google's answer to a live RCE is migrate to Antigravity.

🔍 What happened

  • AIR Security researchers Or Nevo, Dor Granat, and Niv Hoffman published Plugin4Shell on September 17. The Register and Heise covered it September 17 and 18.
  • The bug: agents pin plugins to a git commit SHA, but git resolves a branch named as that SHA first via FETCH_HEAD. An attacker who can push a branch controls what the pin fetches.
  • Auto-update makes it zero-click. The malicious code runs the next time the agent refreshes plugins.
  • Reported in June. Anthropic fixed Claude Code in 2.1.179 and OpenAI fixed Codex in 0.146.0.
  • Google said Gemini CLI is being deprecated and pointed users to Antigravity. Microsoft has not responded and GitHub Copilot remains unpatched.
  • GitHub rejects branch names that look like SHAs. Marketplaces hosted on Bitbucket remain exploitable.

💬 Smart takes

  • AIR Security, in the write-up: a "first-of-its-kind AI supply-chain attack" that hands attackers the keys to the kingdom on developer machines.
  • The Register: the exposure is worst for Copilot because roughly 90 percent of the Fortune 500 use it.
  • Skeptic: the attacker still needs push access to a plugin repo or a marketplace on Bitbucket. Popular plugins on GitHub are shielded by the branch-name block.

🧭 Where this goes

  1. LikelyMicrosoft ships a Copilot patch within two weeks once press coverage forces the issue.
  2. Likelyagent vendors move plugin pinning from git refs to content-hashed archives.
  3. Possibleenterprises turn off plugin auto-update in coding agents by policy, the way they did for browser extensions.
  4. Wild Carda real compromise of a popular plugin ships before Copilot patches, and the incident is named after this bug.

🥄 The Spoon Take

The bug is boring. The response is the story. Anthropic and OpenAI patched. Google said use a different product. Microsoft said nothing, and it owns the agent sitting in most of the Fortune 500. Coding agents now run with your production keys. Treat their plugin systems like browser extensions in 2010.

🤔 Pushback

Exploitation needs push access to a plugin repo, and GitHub-hosted plugins are already shielded by the branch-name block.