• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    AI Coding Agent Git Checkout to Ambiguous 40-hex SHA/Ref

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•0

    Detects Git checkout operations executed by AI coding agent processes that specify a full 40-character commit hash or use 'FETCH_HEAD'. This behavior is indicative of potential supply chain attacks, specifically the 'Plugin4Shell' vulnerability, where malicious actors attempt to force the agent to checkout arbitrary, potentially malicious, repository references.

    Sigma

    Tags

    T1677 - Poisoned Pipeline ExecutionTA0002 - ExecutionProcess CreationCommand ExecutionWindowsWindows Sysmon

    Found in

    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?