The Matthew Chapman Podcast

Plugin4Shell Bypasses Pins on Four AI Coding Agents

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 5:04
Here is your briefing for Friday, September 18, 2026. Air Security disclosed Plugin4Shell, a zero-click supply-chain flaw that defeats SHA pinning in four major A.I. coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini C.L.I. The agents check out a marketplace-pinned commit but never verify that the working tree actually matches it. On hosts that allow a branch named like a forty-hex hash, an attacker who controls the plugin repo can swap in malicious code while the pin still looks honored, and auto-update turns that into a silent replace on machines that already trust the plugin. Anthropic patched Claude Code in two point one point one seventy-nine, and OpenAI fixed Codex in zero point one forty-six point oh. GitHub Copilot still has no fix, and Google will not patch the deprecated Gemini C.L.I., pointing users at Antigravity instead. Default GitHub marketplaces are safer because GitHub rejects hash-shaped branch names, but Bitbucket and self-hosted git remain in the blast radius. If your coding agent can install plugins, update Claude Code and Codex now, audit Copilot plugins, and treat marketplace pins as a promise the agent still has to enforce. Check Point is shipping LivePatch for a critical stack overflow in the unauthenticated login path on Security Management and Log Servers, C.V.E. twenty twenty-six dash ninety-one thousand eight hundred forty-three, scored nine point eight. No credentials required. Overflow the username field before auth finishes, and remote code execution as root is on the table for the box that writes firewall policy and holds the logs. Affected builds include R eighty-two point ten through Jumbo Take forty-four, R eighty-two through Take one twenty-six, and R eighty-one point twenty through Take one sixty-six, plus older end-of-support branches. Check Point says it has no evidence of exploitation yet. Hunt SmartConsole and admin login logs for Username too long, then patch via sk one million one hundred fifty-five. Your management plane is not a place to wait for honeypots. OpenSourceMalware flagged thirteen npm packages delivering a new JavaScript stealer called WeaselBiscuit, a stripped-down cousin of North Korea's BeaverTail and OtterCookie tooling from Contagious Interview. Import triggers a loader that pulls the payload from an Npoint dead drop, runs it in memory, profiles the host, and vacuums Chrome extension storage across Windows, Mac, and Linux, including wallet-extension state. On Windows it can also take clipboard and keystrokes on command. Attribution is still soft, but the tradecraft rhymes: Npoint dead drops, nested geolocation lookups, and numeric campaign I.D.s. The packages include names under the biz forty-four scope plus process-runtime-utils, process-tailwind, and similar decoys. Purge anything matching that list, rotate tokens that lived in extension storage, and remember that a tiny npm import is still a full code-execution foothold. Docker warned that malicious code inside a Docker Sandboxes V.M. on macOS could escape the shared project directory and read or rewrite arbitrary host files as the V.M.M. user, C.V.E. twenty twenty-six dash seventy-seven thousand one hundred seventy-nine, scored nine point four. The virtio-fs host server followed symlinks when reopening a removed path, so a guest that swaps a parent directory for a symlink walks out of the sandbox. That is especially ugly when the guest is a coding agent or whatever that agent just installed. Versions zero point twenty-eight through zero point forty-one on macOS are affected. Fixed in zero point forty-two point oh on September seventh, with zero point forty-three point oh already out. A second high-severity Unix-socket relay bug landed in the same release. No exploitation reported. If you sandboxed agents for safety, update Sandboxes now, or run clone mode and drop read-write host mounts until you can. A sandbox that writes your home directory is just a polite jailbreak. Ars Technica covers Lasso Security research showing Google's SynthID-Text watermarking can change more than word choice. Because the watermark nudges next-token sampling, it can also change tool calls and whether a model refuses a harmful request, especially under prompt injection. On several open-weight models, watermarking made the model more likely to answer requests it would otherwise refuse. That matters because Anthropic has said future Claude models will use SynthID-Text, and the E.U. A.I. Act is pushing machine-readable provenance marks into production. Provenance is not free. Retest safety and agent tool use with the exact watermark config enabled, not the unmarked eval suite you used last quarter. A compliance checkbox that quietly moves your refusal boundary is still a security control change. Plugin4Shell turning trusted agent plugins into zero-click R.C.E., a perfect-ten Check Point management overflow before login, thirteen npm packages shipping WeaselBiscuit into Chrome extension storage, Docker Sandboxes walking out onto the Mac host, and SynthID watermarking nudging models toward answers they used to refuse. Your coding agents, firewall managers, package installs, and provenance knobs are all live attack surface this morning. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show