Hacker NewsClinejection Supply Chain Attack 4000 Developer Machines via Prompt InjectionGrith AI·high signalXBlueskyLinkedInCopy linkGitHub issue title prompt injection exploited Cline AI triage bot, poisoned npm cache, published malicious [redacted] to 4000 devsSourceSource pageGrith AI↳ Follow the threadShared entity / Stack layerMagnitude is a local-inference server that plugs into eight existing coding agents rather than replacing themGitHub TrendingPolicy dependency / Stack layerMoadim Ships an MIT-Licensed Scheduler That Runs Coding Agents on a Cron Instead of a PromptMoadim, via Hacker News Show HNStack layer / Threat patternAstra's prompt-injection attack success rate is 8.5% against 27.0% for GPT-5.6 Sol on Gray Swan's IPI ArenaOpenAI Deployment Safety HubStack layer / Threat patternGitHub's HydraFusion picks a single, cascade or critique workflow per request and cuts TerminalBench cost 67% while gaining pointsGitHub BlogStack layer / Threat patternGitHub Ships HydraFusion, a Copilot CLI Mode That Routes Between Opus 5 and GPT-5.6 Sol Per TaskGitHub Blog / Hacker NewsStack layer / Threat patternCVE-2026-85675: OWL's document tool fetches any URL a prompt injection hands it, and returns the body to the agentNVDStack layer / Threat patternNine advisories land on CodeWhale in one day, including a critical SSRF bypass that beats DNS pinning via a TOCTOU on resolution failureGitHub Security AdvisoriesStack layer / Threat patternAlcaTRAz Defends Jailbreaks With Character-Level Perturbation Rules and No Model Access, Beating Llama Guard on 73.4% of CombinationsarXiv 2609.03693