BREAKING
Clean GitHub Repo Tricks AI Agents
How The Attack Chain Works
1Clone clean repo
2Init raises error
3Agent runs fix
4DNS payload runs
5Reverse shell
Payload Hides In a DNS TXT Record
Repo Inspection vs Runtime Behavior
RepositoryLooks clean
No malicious code
Passes static scans
Survives code review
RuntimeCompromised
Fetches DNS payload
Opens reverse shell
Leaks API keys & tokens
PoC by Mozilla 0DIN, No Exploits Yet
Verify AI Setup Steps Manually
AI NEWS BLITZ
Researchers showed a repo with no malicious code can still make AI coding agents run malware.