<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Developer Security</title><description>Cybersecurity articles tagged #Developer Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>VS Code Marketplace Abuse: Detecting Malicious Developer Extensions</title><link>https://runtimerebel.com/blog/vs-code-marketplace-abuse-detecting-malicious-developer-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-marketplace-abuse-detecting-malicious-developer-extensions</guid><description>Researchers identify malicious Visual Studio Code extensions exfiltrating source code and credentials. Learn how to secure your development environment.</description><pubDate>Mon, 27 Jul 2026 03:19:47 GMT</pubDate><category>VS Code</category><category>Marketplace Security</category><category>Developer Security</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>AI-Generated Code Vulnerabilities: Framework Pairing is Key to Risk</title><link>https://runtimerebel.com/blog/ai-generated-code-vulnerabilities-framework-pairing-is-key-to-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-code-vulnerabilities-framework-pairing-is-key-to-risk</guid><description>AI-generated code introduces an average of 15 vulnerabilities per codebase. This analysis explores how framework choices significantly influence the actual security risk.</description><pubDate>Tue, 21 Jul 2026 13:56:54 GMT</pubDate><category>AI Generated Code</category><category>Code Security</category><category>Application Security</category><category>Vulnerabilities</category><category>Developer Security</category><category>Secure Development</category></item><item><title>AI-Generated Workflows: Hidden Vulnerabilities &amp; Control Gaps</title><link>https://runtimerebel.com/blog/ai-generated-workflows-hidden-vulnerabilities-control-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-workflows-hidden-vulnerabilities-control-gaps</guid><description>Explore the silent security disaster of AI-generated workflows. Understand hidden vulnerabilities, control gaps, and the critical need for human oversight in AI-driven…</description><pubDate>Tue, 30 Jun 2026 16:49:06 GMT</pubDate><category>AI Security</category><category>Workflow Automation</category><category>Shadow IT</category><category>Supply Chain Risk</category><category>Developer Security</category></item><item><title>Claude Code Indirect Prompt Injection: Hijacking Developer Machines</title><link>https://runtimerebel.com/blog/claude-code-indirect-prompt-injection-hijacking-developer-machines</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-indirect-prompt-injection-hijacking-developer-machines</guid><description>Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in…</description><pubDate>Mon, 29 Jun 2026 17:07:49 GMT</pubDate><category>Claude Code</category><category>Prompt Injection</category><category>Supply Chain Attack</category><category>Developer Security</category><category>AI Security</category><category>Reverse Shell</category><category>Machine Hijack</category></item><item><title>AI Agent Malware Evasion: Hidden Payloads via GitHub Repos</title><link>https://runtimerebel.com/blog/ai-agent-malware-evasion-hidden-payloads-via-github-repos</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-malware-evasion-hidden-payloads-via-github-repos</guid><description>Novel technique exploits AI coding agents to execute undetectable malware from clean GitHub repositories, bypassing security scanners and human review.</description><pubDate>Sat, 27 Jun 2026 16:29:10 GMT</pubDate><category>AI Security</category><category>GitHub Security</category><category>Supply Chain Attack</category><category>AI Coding Agents</category><category>Malware Evasion</category><category>Developer Security</category></item><item><title>Agentjacking: Tricking AI Coding Agents into Malicious Code Execution</title><link>https://runtimerebel.com/blog/agentjacking-tricking-ai-coding-agents-into-malicious-code-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentjacking-tricking-ai-coding-agents-into-malicious-code-execution</guid><description>Agentjacking is a new attack where crafted Sentry error reports trick AI coding agents into executing arbitrary code on developer systems, risking intellectual property…</description><pubDate>Fri, 12 Jun 2026 13:18:34 GMT</pubDate><category>Agentjacking</category><category>AI Coding Agents</category><category>Sentry</category><category>Malicious Code Execution</category><category>Developer Security</category><category>Supply Chain Attack</category></item><item><title>IronWorm: Rust-Written Malware Hits npm Supply Chain Developers</title><link>https://runtimerebel.com/blog/ironworm-rust-written-malware-hits-npm-supply-chain-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/ironworm-rust-written-malware-hits-npm-supply-chain-developers</guid><description>Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.</description><pubDate>Fri, 05 Jun 2026 01:01:31 GMT</pubDate><category>IronWorm</category><category>Rust</category><category>NPM</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension</title><link>https://runtimerebel.com/blog/github-repository-breach-3800-repos-accessed-via-vs-code-extension</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-repository-breach-3800-repos-accessed-via-vs-code-extension</guid><description>GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.</description><pubDate>Wed, 20 May 2026 09:15:55 GMT</pubDate><category>GitHub</category><category>VS Code</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments</title><link>https://runtimerebel.com/blog/shai-hulud-worm-code-leak-how-clones-threaten-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-worm-code-leak-how-clones-threaten-developer-environments</guid><description>The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.</description><pubDate>Mon, 18 May 2026 20:37:43 GMT</pubDate><category>Shai Hulud</category><category>Worm</category><category>Developer Security</category><category>Source Code Leak</category><category>Malware Analysis</category></item><item><title>Developer Workstations: The New Front in Software Supply Chain Attacks</title><link>https://runtimerebel.com/blog/developer-workstations-the-new-front-in-software-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/developer-workstations-the-new-front-in-software-supply-chain-attacks</guid><description>A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.</description><pubDate>Mon, 18 May 2026 13:23:15 GMT</pubDate><category>NPM</category><category>PyPI</category><category>Docker Hub</category><category>CI CD Security</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>Supply Chain Attack: Bitwarden CLI npm Package Compromised</title><link>https://runtimerebel.com/blog/supply-chain-attack-bitwarden-cli-npm-package-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/supply-chain-attack-bitwarden-cli-npm-package-compromised</guid><description>Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.</description><pubDate>Thu, 23 Apr 2026 20:25:37 GMT</pubDate><category>Bitwarden</category><category>NPM</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Developer Security</category><category>CLI</category></item><item><title>Cursor AI RCE via Indirect Prompt Injection — Mitigation Guide</title><link>https://runtimerebel.com/blog/cursor-ai-rce-via-indirect-prompt-injection-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cursor-ai-rce-via-indirect-prompt-injection-mitigation-guide</guid><description>Security researchers demonstrate how indirect prompt injection in Cursor AI could lead to full shell access on developer workstations. Patch immediately.</description><pubDate>Fri, 17 Apr 2026 08:43:51 GMT</pubDate><category>Cursor Ai</category><category>RCE</category><category>Prompt Injection</category><category>Developer Security</category><category>Johann Rehberger</category></item><item><title>GitHub Malware Campaign: Fake VS Code Alerts Target Developers</title><link>https://runtimerebel.com/blog/github-malware-campaign-fake-vs-code-alerts-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-malware-campaign-fake-vs-code-alerts-target-developers</guid><description>Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.</description><pubDate>Fri, 27 Mar 2026 20:15:23 GMT</pubDate><category>GitHub</category><category>Visual Studio Code</category><category>Phishing</category><category>Malware</category><category>Infostealer</category><category>Developer Security</category></item><item><title>Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking</title><link>https://runtimerebel.com/blog/anthropic-patches-claude-code-vulnerabilities-enabling-silent-hacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-patches-claude-code-vulnerabilities-enabling-silent-hacking</guid><description>Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.</description><pubDate>Thu, 26 Feb 2026 16:27:39 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>RCE</category><category>Prompt Injection</category><category>Developer Security</category><category>Check Point Research</category></item><item><title>Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware</title><link>https://runtimerebel.com/blog/microsoft-warns-of-fake-next-js-repos-delivering-in-memory-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-warns-of-fake-next-js-repos-delivering-in-memory-malware</guid><description>Microsoft warns developers of a coordinated campaign using malicious Next.js repositories disguised as job assessments to deliver in-memory malware.</description><pubDate>Thu, 26 Feb 2026 12:20:28 GMT</pubDate><category>Next Js</category><category>Social Engineering</category><category>In Memory Malware</category><category>Developer Security</category><category>Microsoft Threat Intelligence</category><category>GitHub</category></item><item><title>AI Code Generation Poses Supply Chain Risk to Developer Machines</title><link>https://runtimerebel.com/blog/ai-code-generation-poses-supply-chain-risk-to-developer-machines</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-code-generation-poses-supply-chain-risk-to-developer-machines</guid><description>Learn how AI-generated code, like from Anthropic&apos;s Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…</description><pubDate>Thu, 26 Feb 2026 00:34:32 GMT</pubDate><category>AI Security</category><category>Software Supply Chain</category><category>Developer Security</category><category>Code Generation</category><category>Anthropic Claude</category><category>Malicious Code</category></item></channel></rss>