Articles

Long-form, technically grounded analysis on AI agent security — structural controls, real incidents, and the thinking behind them. No fluff, no hedging.

prompt-injectionsupply-chainai-dev-toolsnpmci-cdagentic-securityclinejection

Clinejection: How a GitHub Issue Title Compromised 4,000 Developer Machines — and Why Your AI Dev Tooling Is Next

One crafted GitHub issue title. One triage bot that couldn't tell the difference between a developer instruction and an attacker payload. One backdoored npm release. Four thousand machines. Clinejection isn't a novel attack — it's a template for what happens when AI dev tooling holds privileged supply chain access and trusts the wrong inputs.

Ofir Stein·March 8, 2026·Making Of included