[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-researchers-trojanize-ai-coding-agents-through-update-hooks":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},6064,"researchers-trojanize-ai-coding-agents-through-update-hooks","Researchers Trojanize AI Coding Agents Through Update Hooks","A new attack tool shows plugin update hooks can silently hijack AI coding agents with host-level privileges, and most security software misses it.","AI coding agents will run malware buried inside a routine plugin update, no questions asked.\n\nResearchers found that many AI agent harnesses expose \"lifecycle hooks\" - configuration that binds shell commands to events like session start, tool calls, or file edits. Those commands run with full host privileges, and they can fire without the underlying LLM ever seeing them. The team built HookPry, an open-source and fully automated attack framework, to show that an attacker who controls only a plugin's metadata and hook configuration can trojanize an already-trusted, versioned plugin. A routine-looking update silently attaches malicious commands to benign events, with no review of the agent's actual behavior required. Across 1,000 end-to-end runs spanning 25 combinations of harnesses and backends, HookPry pulled off ten distinct attack objectives, including privilege escalation, and compromised all seven harnesses tested, with per-harness success rates as high as 92.5%.\n\nThe real story here is what harnesses choose to trust. Prompts and generated code get scrutiny; lifecycle-hook configuration apparently does not, even though it runs with the same privileges as anything else on the host. That gap turns a boring version bump into a plausible attack vector, and the defenses meant to catch it barely register: Microsoft Defender flagged none of the malicious artifacts, and combining three static-analysis tools still missed 47.5% of them.\n\nThis is the same trick as dependency confusion or typosquatted packages, just aimed at a part of the stack nobody thinks to audit. Config isn't supposed to be where the exploit lives - which is exactly why it worked.","[\"ai agents\",\"supply-chain attacks\",\"security research\",\"vulnerabilities\"]","2026-09-04T04:00:00.000Z","2026-09-04T06:16:42.799Z","2026-09-04T06:16:54.702Z","published",null,[],"security",[26,27,28,29],"ai agents","supply-chain attacks","security research","vulnerabilities",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.03884",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,96,101],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",565,"2026-09-05T00:03:08.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",300,"2026-09-04T22:18:34.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]