The danger has moved into the trust path itself. Once an attacker poisons the tiny harness files an AI coding assistant reads on project open, the assistant can keep re-running the payload inside normal developer workflows without a new code commit to spot.
Tenable says Mini Shai-Hulud variants now rewrite assistant configs such as `settings.json` and `.cursorrules`, so the hook fires each time the IDE opens a project. Island separately found about 7,600 fake GitHub repositories in the FakeGit campaign, with more than 800 posing as AI Skills or MCP servers and AI agents surfacing them to users; that operation used SmartLoader to establish persistence and drop StealC.
The forward risk is a built-in distribution channel inside developer tools. If your assistants can read project files or run actions, poisoned harness configs can keep re-triggering across sessions and spread through the same workflows teams trust for everyday development.