Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code
A developer embedded a prompt injection attack in open-source code. It targets AI coding agents. This is what happens when humans and AI agents write code together.

Why it matters
As AI agents become primary code contributors, malicious prompt injections embedded in dependencies pose a novel supply-chain security risk that current tooling doesn't detect. This signals a broader vulnerability class in agent-driven development workflows.
The key facts
6 to knowPrompt injection discovered in jqwik library
Attack targeted AI coding agents, not humans
Malicious instruction: delete app output/data
Embedded in open-source dependency
Suggests growing tension between human developers and AI-driven workflows
Highlights detection gap in agent-based code review processes
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: Undisclosed addition in jqwik instructed AI coding agents to delete app output.
