Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
Cursor’s agent could write to .git/hooks/ — planted hook scripts execute on the next commit/push/checkout with full OS privileges, no further prompt needed. Fixed in 2.5; the class persists in every file-writing agent.
34+ malicious packages (384 versions) planted .cursorrules/CLAUDE.md with invisible zero-width-Unicode instructions. First documented at-scale attack on the agent instruction channel itself.
A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.
Five campaigns, one phenomenon: 1,000+ compromised packages, AI-targeting malware hunting ~/.claude, ~/.cursor, ~/.codex configs and LLM API keys. Your AI assistant is both weapon and target.