Three vectors, one target: standing credentials.
covered below
against agent tooling
incidents + CVEs, cumulative
TrapDoor poisons the files your agent reads first
Socket tracked 34+ malicious packages across npm, PyPI and crates.io that hid instructions in zero-width Unicode inside CLAUDE.md and .cursorrules, so AI assistants reading those files ran credential theft disguised as a security scan. The actor also filed pull requests trying to land the poisoned configs in major AI projects as development standards.
Composio breach: one token, 10,242 doors
One stolen employee Gmail OAuth token let an attacker pivot through an internal monitoring tool into the credential store of the agent-integration platform: 5,001 GitHub OAuth tokens, 5,241 API keys and 12 Gmail tokens exposed, plus Jira, Slack, HubSpot, Linear, Notion and Google Calendar tokens. Company-wide rotation followed within two days.
Morse-code injection drains a Grok-linked agent wallet
A Morse-coded reply on X tricked Grok into decoding a transfer order and tagging the Bankr trading agent, which executed the output as an authenticated command: roughly 3B DRB tokens, reported at $150K to $200K, left the wallet on Base. Most of the value was returned after negotiation.
A config file, a SaaS credential store, another agent’s words. Different doors, same room: wherever real keys sit ready to use, everything that can read them is attack surface.