{
  "id": 10241140,
  "title": "Plugin4Shell Hit 26,000 Agents Before Anyone Noticed. Your Coding Agent’s Plugin Store Is the New npm.",
  "url": "https://urgent.news/2026/09/27/plugin4shell-hit-26-000-agents-before-anyone-noticed-your-coding",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-27T15:49:30.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/numbpill3d/plugin4shell-hit-26000-agents-before-anyone-noticed-your-coding-agents-plugin-store-is-the-new-5hlg"
  },
  "original_language": "en",
  "account": "A zero-click remote code execution (RCE) vulnerability, dubbed Plugin4Shell, affected over 26,000 AI coding agents before it was addressed in May 2026. Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI were all vulnerable. The exploit stems from the way these agents handle plugin updates. They check out a SHA-pinned commit, but they don't verify that the checked-out code matches that commit. Attackers can exploit this by creating a branch with the same 40-character hex string as the pinned SHA, tricking the agent into checking out the malicious branch instead. This silent, zero-click attack can retroactively weaponize previously installed plugins, affecting not just the software but potentially the entire CI pipeline. The vulnerability highlights the pressing need for better security measures in AI coding agent plugin marketplaces, which have adopted supply chain attack patterns from traditional package managers like npm, PyPI, and RubyGems.",
  "summary": "A zero-click RCE vulnerability across Claude Code, Codex, Copilot, and Gemini CLI proves that AI coding agent plugin marketplaces have inherited every supply chain attack pattern from package managers, plus some new ones. In May 2026, researchers at Air Security discovered that every major AI coding agent handles plugin updates the same way: it checks out a SHA-pinned commit, but it never…",
  "key_points": [
    "Over 26,000 AI coding agents affected by Plugin4Shell vulnerability before May 2026",
    "Exploit exploits SHA-pinned commit handling, allowing attackers to deploy malicious branches",
    "Highlights need for improved security in AI coding agent plugin marketplaces"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}