AI coding tools can add risks to your projects

Published July 30, 2026

AI coding assistants can now pick, install, and run outside code on their own, often without a person checking it first. Attackers are starting to target those automated decisions to slip malicious code into software projects.

Report priority
Medium
Targets
MCP servers+4 more

How it works

Attackers compromise trusted package maintainer accounts, hide malicious code inside indirect dependencies a project pulls in automatically, or plant hidden instructions in files and web content that trick an AI coding agent into installing or running unsafe code using the developer's own access.

What to do

The risk applies to any team using AI coding tools that install dependencies, connect to MCP servers, or add IDE extensions without a human reviewing each one first.

Require human review before an AI coding agent installs or runs a new package, MCP server, or extension, and use a dependency scanning tool that flags known malicious packages before they reach your project.

Technical details

Affected software: MCP servers, Axios, TanStack, Trivy, IDE extensions

At AI Council 2026, Socket founder Feross Aboukhadijeh described how coding agents can autonomously select, install, and execute third party npm packages, MCP servers, and IDE extensions using a developer's own credentials, often with no human review step. He referenced 2026 supply chain incidents tied to Axios, TanStack, and Trivy, where compromised maintainer accounts, malicious transitive dependencies, and prompt injection let attackers reach both developers and their agents. Traditional supply chain security tooling assumes a human vets each dependency; that assumption breaks down once agents make these trust decisions at machine speed.

References