Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Geordie Watch posted an update

A summer 2026 coding-agent session pulled in a malicious npm package linked to the Shai Hulud supply-chain worm, according to Geordie. The customer treated it as a critical incident.

Why it matters

Geordie says the customer’s endpoint detection and response system recorded none of the agent’s npm or npx commands and raised no alert. Geordie’s session recording showed the commands and tool calls, the company says, and the customer later asked for detections to feed into its security workflows. It is a vendor’s account of an unnamed customer incident, not an independent investigation. But it makes a practical point for teams using coding agents: endpoint monitoring may not show what an agent does inside its session.

Discuss: Should companies treat AI coding agents as a separate security-monitoring problem, or should existing endpoint tools be expected to cover their activity?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.