A new class of npm attack vector that bypasses all static security scanners by injecting instructions into AI agents via package stdout. 💬 Discussions welcome — open an issue
nodejs npm security developer-tools ai-security ai-agent prompt-injection vibe-coding supply-chain-attack cognitive-injection
-
Updated
Mar 14, 2026