The Miasma Worm Specifically Targeted AI Coding Tools - Have You Changed Your Setup

Started by KnotKnull, Jun 14, 2026, 08:10 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: The Miasma Worm Specifically Targeted AI Coding Tools - Have You Changed Your Setup   Views(Read 61 times)

KnotKnull

The technical detail that distinguishes the Miasma worm is worth understanding if you use AI coding assistants professionally. The attack planted a .claude/settings.json file containing a SessionStart hook, meaning the credential harvesting payload fired automatically when a developer opened the repository in Claude Code. Similar files targeted Gemini CLI, Cursor and VS Code. The attack did not require running anything manually.

Has this changed how you have configured your tools? What permissions do your coding assistants actually have, and has anyone audited their setup since this came out?
If I had to write my strongest quantum signature, it would be: everything starts in superposition.

Amber_44

Audited my Claude Code permissions immediately after reading the StepSecurity write-up. It had broader filesystem access than I had intentionally granted. The default settings are generous in ways not obvious from the onboarding

Vanessa26

We have added a pre-open script at work that checks for unexpected config files in repositories before anyone opens them in an AI coding tool. Adds friction but feels necessary

FrostCandle

The SessionStart hook mechanism is elegant from an attacker's perspective. It requires no user action beyond the normal workflow. That is a new attack surface
Football is life. Everything else is just details.

Connor82

Pinned all my dependencies to exact commit SHAs. This was best practice before Miasma and remains so. If you are using floating version references in CI/CD please stop

ClaudioHerrera

I think the broader point is that AI coding tools have normalised granting software broad system access in exchange for capability. We accepted that tradeoff without fully thinking through the security implications

Rob98

Rotated all secrets from any pipeline that ran after May 20. This was painful but if credentials were harvested during the exposure window we needed clean secrets regardless
Measure twice, post once

Zach

Has anyone found a way to run Claude Code in a properly sandboxed environment without losing too much capability? That feels like the right architectural answer

Ryan84

The attack targeting AI coding tools by exploiting how they handle configuration is significant. The same automation that makes the tools useful is what makes them a viable attack surface
GG no re

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer