Analysis · curated 14 Sep 2026

Stochastic Malware: When Your LLM Randomly Decides to Steal Your Data

Coverage timeline

14 Sep 2026hendrik-erz.de

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Agentic code editors granted unsupervised file and command access can leak credentials or personal data by design, a risk defenders must weigh before deploying autonomous coding agents in sensitive environments.

Hendrik Erz argues that agentic AI coding tools (Claude Code, Copilot, Google Antigravity, Cursor) act as 'stochastic malware' — software that may, without warning, read sensitive files like .env credentials and leak them to the internet. The piece contends that mitigations such as hiding .env files are futile and that these autonomous file-reading, command-running agents cannot verifiably be prevented from exfiltrating data.