Hackers Are Now Trying To Manipulate AI Coding Assistants Directly
-

One of the most alarming parts of the TrapDoor campaign is that it specifically attempts to hijack AI coding assistants like Claude and Cursor through hidden prompt injection techniques. According to researchers, the malware secretly injects instructions designed to trick AI tools into running fake security scans or workflows that expose sensitive credentials and development secrets.This represents a major evolution in cyberattacks because attackers are no longer only targeting humans directly. They are now actively trying to manipulate AI systems integrated into developer workflows. As AI coding assistants become more common across software engineering, these types of attacks could become a growing cybersecurity threat for developers, startups, and large technology companies alike.
-
hackers officially moved beyond phishing humans and started socially engineering the ai assistants instead