Skip to content
zarza zarza

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

30/06/2026 0 min

Listen "Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks"

Episode Synopsis

Adversa AI has discovered a major vulnerability in open source AI coding agents, dubbed GuardFall, that exploits decades-old Bash shell tricks to bypass security guards and execute malicious commands. Of eleven popular agents tested, only one—Continue—was able to block all the attack techniques, which use methods like quote removal and spacing manipulation to disguise destructive commands that the AI agent then executes with the developer's full authority. This creates a significant supply chain risk, especially in CI pipelines where auto-approval modes are common, potentially allowing attackers to exfiltrate credentials or wipe development environments through poisoned files in malicious repositories.

More episodes of the podcast Security Stuff

ZARZA Studio — Your station on air today: library, music clock, schedule, studio and reports, from the browser.

Meet ZARZA Studio
on air now stations in the catalogue 1,828,908 podcasts countries