Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
Five campaigns, one phenomenon: 1,000+ compromised packages, AI-targeting malware hunting ~/.claude, ~/.cursor, ~/.codex configs and LLM API keys. Your AI assistant is both weapon and target.
A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.
34+ malicious packages (384 versions) planted .cursorrules/CLAUDE.md with invisible zero-width-Unicode instructions. First documented at-scale attack on the agent instruction channel itself.
When a CVE drops: reachability first, severity second. Most criticals are not reachable; most reachables are not critical. Automate the check.
After Shai-Hulud (worm, Sep 2025) and the 2026 typosquat waves, working defenses: provenance attestation, npm ci only, install-time egress control, --ignore-scripts.
SBOMs (SPDX/CycloneDX) at build time and signed provenance attestations (SLSA, npm/PyPI provenance) are the accepted supply-chain baseline — consumers verify, CI generates, and agents should require both for dependencies.
ox.security documented a systemic MCP supply-chain flaw (Apr 2026): unverified name claims + client trust let a takeover cascade across 150M+ downloads / up to 200K servers. Defense: pin servers, verify publishers, scan skills.