Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks AI security researchers at Adversa AI discovered a structural security flaw called GuardFall that exploits decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. Attackers can hide malicious commands in repositories, README files, or Makefiles, potentially enabling credential theft, system compromise, or software supply chain attacks. Of 11 popular open source AI coding agents tested, only one successfully blocked all the Bash trick techniques. Slashdot reader wiredmikey writes: AI security researchers have uncovered a structural security flaw dubbed GuardFall that allows decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. By exploiting shell behaviors such as quote removal and variable expansion, attackers can hide malicious commands in repositories, README files, Makefiles, or other content consumed by AI agents. If executed — particularly in auto-approve or CI environments—the commands can steal credentials, compromise developer systems, or enable software supply chain attacks. According to researchers at Adversa AI, the 11 popular open source AI coding agents tested, only one successfully blocked all of the Bash trick techniques. Read more of this story https://linux.slashdot.org/story/26/07/04/0325244/decades-old-bash-tricks-expose-ai-coding-agents-to-supply-chain-attacks?utm source=rss1.0moreanon&utm medium=feed at Slashdot.