Roman Imankulov nearly installed malicious code from a fake recruiter. He spun up a VPS on Hetzner and used a Pi coding agent running Codex for read-only analysis. The AI flagged a backdoor in app/test/index.js that would execute commands from a remote server.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Agentjacking attack hijacks AI coding agents via fake bug reports