'Agentjacking' attacks trick coding agents into running malicious code
A newly documented attack pattern hijacks AI coding agents mid-session, turning their own tool access against the developer.

- ▸Security researchers have documented "Agentjacking," an attack pattern targeting AI coding agents
- ▸The attack tricks agents into executing malicious code during a legitimate session
- ▸It exploits the same tool-calling access developers grant agents to do their job
- ▸The disclosure adds to a growing body of 2026 research on AI coding agent supply-chain risk
Trusted access becomes the attack surface
Agentjacking is notable because it doesn't need to break into anything — it hijacks the legitimate permissions a developer already granted their coding agent, turning routine tool access into the delivery mechanism for the attack.
Source: The Hacker News


