AI Assistants Become a Malware Distribution Layer

The danger has moved into the trust path itself. Once an attacker poisons the tiny harness files an AI coding assistant reads on project open, the assistant can keep re-running the payload inside normal developer workflows without a new code commit to spot. Tenable says Mini Shai-Hulud variants now rewrite assistant configs such as `settings.json` and `.cursorrules`, so the hook fires each time the IDE opens a project. Island separately found about 7,600 fake GitHub repositories in the FakeGit campaign, with more than 800 posing as AI Skills or MCP servers and AI agents surfacing them to users; that operation used SmartLoader to establish persistence and drop StealC. The forward risk is a built-in distribution channel inside developer tools. If your assistants can read project files or run actions, poisoned harness configs can keep re-triggering across sessions and spread through the same workflows teams trust for everyday development.

Part of the PlainSec briefing for 2026-07-21

Sources