A new type of attack on artificial intelligence (AI) coding agents lets threat actors convince users to give permission to the AI to do dangerous things that ultimately could result in a software supply chain attack. They proved their attack — which they characterized as a remote code execution (RCE) via prompt injection attack — on Anthropic's AI code assistant Claude Code. However, the attack "exploits the intersection of agentic tooling and human fallibility" and can be applied to any AI agent that relies on "human-in-the-loop" (HITL) interactions to approve an AI action for safety or security reasons. The researchers first lied by creating a GitHub issue, then asked the AI agent to take care of the issue. Security of AI Agents Remains in DoubtOrganizations are increasingly adopting AI agents as part of their employees' daily routines, with 79% of organizations already adopting AI-assisted coding agents into at least some workflows, according to CheckMarx Zero.