THREATOPS
THREAT OPSThreat News › Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness

Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness

medtenablePublished 2026-07-21

<p>Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' own tools.</p><h2>Key takeaways</h2><ol><li>AI coding assistant configuration files, such as <em>settings.json</em> ho

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.tenable.com/blog/ai-coding-assistant-agent-harness-attacks