The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection

First reported 2 Jun 2026 · 25d ago

Coverage timeline

2 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

It demonstrates that open source maintainers can weaponize dependencies with concealed prompt injections against AI coding agents, posing a real supply-chain risk to developers using LLM-based tooling.

The jqwik 1.10.0 release added a hidden prompt injection targeting AI coding agents, using terminal escape codes to conceal destructive instructions from humans while keeping them readable to logs and tools. This was introduced by the open source maintainer as protestware against agentic coding.

Why it matters

It demonstrates that open source maintainers can weaponize dependencies with concealed prompt injections against AI coding agents, posing a real supply-chain risk to developers using LLM-based tooling.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS