• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    AI Coding Agent Spawns Shell/Script Interpreter Post-Plugin Checkout

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•5

    Detects when AI-powered development tools or coding assistants (such as Claude, Copilot, Gemini, or Codex) spawn suspicious child processes like command shells (cmd, powershell, bash, sh) or networking utilities (curl, wget, python). This behavior is highly atypical for integrated development environments and may indicate exploitation of the assistant's integration or malicious code execution.

    Cortex XDR

    Tags

    T1059 - Command and Scripting InterpreterT1059.001 - PowerShellT1059.003 - Windows Command ShellT1059.004 - Unix ShellTA0002 - ExecutionProcess CreationCommand ExecutionWindowsLinuxmacOS

    Found in

    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?