← Founder Notes
Archive

The first supply-chain attack on coding agents is already here. plugin4shell, disclosed september…

Yethikrishna ROriginal on Threads

the first supply-chain attack on coding agents is already here. plugin4shell, disclosed september 17, is a zero-click flaw that defeats sha pinning and swaps pinned plugin code inside claude code, codex, copilot and gemini cli, and only two of the four vendors have patched.

your agent's marketplace trust just became the attack surface.

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 24 September 2026 at 03:52 IST.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-first-supply-chain-attack-on-coding-agents-DdpX4htCDcR" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The first supply-chain attack on coding agents is already here. plugin4shell, disclosed september…"></iframe>

More notes