An automated attack campaign compromised thousands of GitHub repositories through malicious commits in development processes, targeting the software supply chain rather than production vulnerabilities.
AI coding agents can be manipulated via compromised symlinks to silently register malicious server code that executes with user privileges on restart, endangering secrets and CI infrastructure.