Executive Summary
Security researchers have identified a pattern of activity termed 'Living off the Coding Agent,' where signed GenAI tools like Claude Code and Cursor are utilized as execution parents for malicious or high-risk behaviors. By using these trusted binaries to spawn shells, attackers can bypass initial scrutiny, performing credential theft and deploying persistence mechanisms that appear to be developer-driven workflows.
The attack chain involves leveraging the coding agent's approved status to run dual-use tunnel brokers such as Cloudflare Quick Tunnels, ngrok, and localhost[.]run. This enables remote access to a local workstation without firewall modifications. Persistence is achieved through the creation of macOS LaunchAgents, which ensure the tunnels and their associated watchdog scripts remain active across reboots, potentially exposing internal services to the public internet.
This trend poses a significant challenge for SOC teams because the telemetry mimics legitimate developer activity. The risk to organizations includes the exposure of local admin dashboards, unauthorized credential access, and long-term remote access persistence that evades traditional application control signatures.
