Attack  ·  Glossary

Lifecycle-Hook Supply Chain Attack

A new style of attack that hides malicious instructions in the setup or configuration steps an AI coding agent runs automatically — before its safety sandbox or human-approval checks ever kick in. Because the code runs at 'startup', not during the AI's normal reasoning, standard AI guardrails never see it.
This defeats the safety promise organizations rely on when they let AI coding agents operate semi-autonomously, and researchers showed it works across seven major agent platforms with a single automated exploit.
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →