Plugin4Shell: Your AI Coding Agent's "Pinned" Dependency Was Never Actually Pinned
Security researchers at AIR disclosed Plugin4Shell, described as the first supply chain vulnerability in the AI agent ecosystem, showing that Claude Code, Codex, GitHub Copilot, and Gemini CLI check o…