Skip to main content
Mallory
Back to intelligence
ai-platform-securitybuild-pipeline-compromisevendor-distribution-compromiseleaked-secret-api-key

SymJack and Malicious AI Skills Expose New Supply-Chain Risks for Coding Agents

Updated 11d agoFirst seen Jun 3, 20262 sources

Researchers disclosed SymJack AI, an attack technique that abuses symbolic links in repositories to trick AI coding assistants and automated development tools into writing to attacker-chosen destinations. A user may approve what appears to be a harmless file change, while the operating system follows a malicious symlink to alter configuration files and enable later command execution with the victim’s privileges. The technique raises concerns for local developer workstations and for CI/CD systems that automatically process untrusted pull requests, where compromised jobs could expose cloud credentials, deploy keys, and other sensitive secrets.

Separate research found that public AI skill marketplaces remain vulnerable to simple malicious submissions that evade automated scanning. Trail of Bits reported bypassing multiple skill scanners with proof-of-concept packages that used oversized files, hidden content in .docx archives, poisoned .pyc bytecode, and prompt-injection-style social engineering to disguise malicious behavior. The findings indicate that both repository-based coding agents and downloadable agent skills can become supply-chain entry points, prompting calls for stricter validation of resolved file paths, tighter controls on configuration writes, monitoring of runtime behavior, review of pull requests that modify agent setup, and the use of curated internal skill sources instead of public marketplaces for sensitive environments.

Share:
SymJack and Malicious AI Skills Expose New Supply-Chain Risks for Coding Agents
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 3, 202612d ago

SymJack AI attack technique is publicly reported

A newly reported attack technique called SymJack AI was disclosed as a way to abuse symbolic links in repositories to achieve remote code execution through AI coding assistants and automated development tools. The report warned that the technique could also threaten CI/CD pipelines that process untrusted code.

SymJack AI Attack Technique Threatens Coding Assistants

Trail of Bits reports malicious AI skill scanner bypasses

Trail of Bits published research showing that multiple AI skill scanners could be bypassed using four proof-of-concept malicious skills, including techniques involving file truncation, hidden content in a .docx archive, poisoned .pyc bytecode, and prompt-injection-style social engineering.

The sorry state of skill distribution - The Trail of Bits Blog
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Affected products
6 linked
VirustotalClaude CodeSnykOpenclawLibreofficeCodex
Organizations
13 linked
Cisco SystemsSocketVirustotalAnthropicAvastTrail of BitsOpenaiSnykLibreofficeVercelGoogleClawHubOpenclaw
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

SymJack and Malicious AI Skills Expose New Supply-Chain Risks for Coding Agents | Mallory