Important 2026 LLM-Based Attack Detection: AI Coding Assistant Prompt Injection

Detects anomalous activity where an AI coding assistant process reads sensitive local credential files (such as .env, .aws/credentials, or SSH keys) followed by an outbound network connection to a destination not associated with known package registries or AI provider APIs. This pattern is indicative of potential prompt-injection attacks targeting autonomous AI coding tools to exfiltrate developer secrets.