Threat hunters at Air, a security startup focused on enterprise AI agent protection, have disclosed a first-of-its-kind AI supply-chain attack they call Plugin4Shell. The exploit targets trusted marketplaces that host plugins for popular coding agents rather than the models or agents themselves, potentially reaching millions of users and machines.
The vulnerability lies in how agents enforce SHA-pinning mechanisms designed to lock plugins to a specific immutable commit hash. According to researchers Or Nevo, Dor Granat, and Niv Hoffman, “The agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored. The result is zero-click remote code execution.”
Agents’ plugin auto-update feature makes this a zero-click attack. An attacker could submit a benign plugin to a marketplace, pass review, and later replace the benign content with malicious code, or hijack a legitimate author’s repository and push malicious updates to every agent with the plugin installed.
Air reported the issue to all vendors in June. Anthropic patched Claude Code in version 2.1.179, and OpenAI patched Codex in version 0.146.0. Google told Air it will not patch the Gemini CLI, having deprecated it, and suggests users migrate to its newer Antigravity agentic development environment instead. Microsoft did not fix the flaw in Copilot. A GitHub spokesperson said the attacks do not affect GitHub, stating “To prevent abuse of SHAs, GitHub does not allow users to create branch or tag names that resemble commit SHAs. This mitigation ensures the reported vulnerability cannot be exploited on GitHub.”
Air researchers countered that the GitHub mitigation is insufficient “because marketplaces can also be hosted in other platforms such as Bitbucket.” The team added, “Microsoft Copilot is also still vulnerable because it supports marketplaces from such platforms as well, which exposes it to the vulnerability.” They reported the issue to Microsoft in June but said they did not receive a response due to the volume of disclosures Microsoft is currently handling. Microsoft did not immediately respond to a request for comment.
The researchers described the exploit as affecting almost 90 percent of Fortune 500 companies that use Copilot, according to Microsoft. They emphasized that “the fix has to ship in the agent, and updating is the only complete mitigation where one exists.”