Three vectors, one target: standing credentials.

Published Jul 30, 2026 · full chronicle
3
named incidents
covered below
12
CVEs at CVSS ≥ 7 filed
against agent tooling
113
tracked events since Apr 2025
incidents + CVEs, cumulative

TrapDoor poisons the files your agent reads first

Socket tracked 34+ malicious packages across npm, PyPI and crates.io that hid instructions in zero-width Unicode inside CLAUDE.md and .cursorrules, so AI assistants reading those files ran credential theft disguised as a security scan. The actor also filed pull requests trying to land the poisoned configs in major AI projects as development standards.

Sources: Socket · The Hacker News

Composio breach: one token, 10,242 doors

One stolen employee Gmail OAuth token let an attacker pivot through an internal monitoring tool into the credential store of the agent-integration platform: 5,001 GitHub OAuth tokens, 5,241 API keys and 12 Gmail tokens exposed, plus Jira, Slack, HubSpot, Linear, Notion and Google Calendar tokens. Company-wide rotation followed within two days.

Sources: Composio · Material Security

Morse-code injection drains a Grok-linked agent wallet

A Morse-coded reply on X tricked Grok into decoding a transfer order and tagging the Bankr trading agent, which executed the output as an authenticated command: roughly 3B DRB tokens, reported at $150K to $200K, left the wallet on Base. Most of the value was returned after negotiation.

Sources: SlowMist · OECD.AI

A config file, a SaaS credential store, another agent’s words. Different doors, same room: wherever real keys sit ready to use, everything that can read them is attack surface.

Get the next report
One email when the next issue ships, plus early access to SafeClaw. Nothing in between.