The SymJack is an innovative threat that exploits developers' trust in AI coding agents, turning them into tools for supply chain attacks. The Adversa AI discovered this method that allows malicious code to silently infiltrate software development processes.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

Malicious repositories are a factor in 20% to 40% of supply chain attacks. SymJack exploits this trend by using three key elements: control of the repository by the attacker, a ready-made malicious MCP server, and the use of AI coding tools by the developer. The attack gets its name because it “hijacks” a symlink within the code development process.
The attack chain begins with the attacker controlling the coding agent repository and the instructions file it contains. This file is made malicious but is used and trusted by the AI agent. In SymJack, a malicious symlink is renamed to appear innocent. A cp can be used to automatically insert the attacker's malicious payload, hidden within the disguised symlink, into the agent's configuration.
The payload registers the malicious MCP server, where the launch command executes whatever the attacker desires. As Adversa: “The developer sees a request: copy this [innocent] file to that documentation folder. He approves it. Nothing on the screen mentions the config folder, the MCP file, or the executable content. On the next reboot, the planted server is activated and the attacker’s code is executed as the user, without a sandbox.”
How SymJack impacts CI/CD systems
If the attack targets the CI , the radius of destruction can be increased without further user interaction. CI runners already contain the secrets necessary for their operation. “ A single malicious pull request can extract all of this before a human has reviewed the change ,” the Adversa report notes. This constitutes a supply chain attack with a coding agent as the delivery mechanism.
See also: Google attributes Axios Supply Chain Attack to UNC1069

Adversa tested its methodology on five major coding agents (Claude Code, Gemini CLI and Antigravity CLI, Cursor Agent CLI, Grok Build CLI, and GitHub Copilot CLI) and found that it worked in all cases. The company reported the issue to all five companies. So far, xAI and GitHub have not responded, and Google has dismissed the report because explicit user consent is considered intended behavior.
Cursor refused , saying it was already aware of the issue, and Anthropic dismissed the issue as out of scope. Despite the initial rejection, Anthropic quietly enhanced Claude Code a few weeks later. “The enhanced version of Claude Code now resolves symlinks before asking for approval and shows the actual destination path in the prompt.”
Protection against SymJack attacks and related threats
The discovery of such trust vulnerabilities as SymJack will likely increase – it is the natural result of over-trust applied to over-automation. Trust and automation have become essential for modern businesses, and both stem from the need for speed to deliver ROI and maintain or improve competitiveness.
Experts recommend restricting the permissions of AI agents so that they cannot read, write, install, or execute freely without explicit policy checks. Also, human approval is required for high-impact actions such as installing dependencies, trusting the repository, publishing packages, and CI/CD. Using allow-lists for tools, releases, registries, and agent plugins/MCP servers rather than allowing local project configuration to escalate privileges is critical.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT

According to the report, maintaining a trusted component registry and favoring verified or proven packages is also important. Organizations should reject packages without explicit source controls when possible and disable install scripts by default in CI and developer workflows.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
