Vibe CodingClinejection Supply Chain Attack Analysis by Willison and SnykSimon Willison·high signalXBlueskyLinkedInCopy linkPrompt injection in GitHub issue title compromised Cline npm publishing tokens via cache poisoning. 4000 developer machines affected in 8-hour window.SourceSource pageSimon Willison↳ Follow the threadStack layer / Threat patternPaul Ford on the paradox of democratized coding: accessibility clarified who shouldn't be relying on AI toolssimonwillison.netThreat patternIndependent researchers pin May's RubyGems package flood on an OpenAI agent swarm that OpenAI never disclosedSimon Willison's Blog (primary report at rubyhack.ai, corroborated by The Verge)Stack layer / Threat patternElva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo CommitsElva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)Stack layer / Threat patternAlibaba's open-code-review shipped v1.12.1 today and claims 4.7x the precision of Claude Code at a fourteenth of the tokensGitHub TrendingPolicy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterStack layer / Threat patternPattern: Anthropic's own bar is that Claude-written production code gets reviewed harder than human-written codeSimon WillisonStack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat patternSnyk put its agent-skill scanner behind a free web page called Skill InspectorSnyk Labs