Signed Coding Agents Can Hide Remote Access

Vendor-signed coding agents can front for the exact behaviors defenders treat as high severity. The parent process looks legitimate, but the shell children can still open reverse tunnels, add persistence, and leak credentials, so allowlisting based on provenance misses the dangerous part. Elastic Security Labs found this on macOS with Claude Code and Cursor. Telemetry showed shell activity under those agents that set up ephemeral tunnels and installed LaunchAgents, with credentials visible on the wire and the same session matching patterns used by common tunnel services. The practical risk is broader than these two products. Any developer laptop that lets an AI coding assistant run shells and touch local apps can hide remote access and persistence inside trusted-looking tooling.

Part of the PlainSec briefing for 2026-08-07

Every edition of this story: Signed Coding Agents Can Hide Remote Access

Sources