π¨ We detected malicious OpenVSX releases of Aqua Trivy (1.8.12 & 1.8.13) that injected natural-language prompts to weaponize local AI coding agents.
Uncategorized
1
Posts
1
Posters
1
Views
-
We detected malicious OpenVSX releases of Aqua Trivy (1.8.12 & 1.8.13) that injected natural-language prompts to weaponize local AI coding agents.The releases occurred during a broader AI-powered attack targeting #OSS projects.
Full analysis β
https://socket.dev/blog/unauthorized-ai-agent-execution-code-published-to-openvsx-in-aqua-trivy-vs-code-extension -
R relay@relay.infosec.exchange shared this topic