The first 19 months of the agent era.

Publicly disclosed incidents, CVEs and malicious packages. Filed chronologically, facts and sources only.

0+
Vulnerabilities & incidents
disclosed 2025 to 2026.07
0+
CVEs at CVSS ≥ 7
against agent tooling
0+
Malicious packages
npm / PyPI / crates.io / skills
0
Named real-world incidents
covered individually below

Getting denser every quarter.

Big dots = named incidents, colored by kind. Small dots = CVEs. Hover for the story.

Jan2025FebMarAprMayJunJulAugSepOctNovDecJan2026FebMarAprMayJunJul
Rogue actionSecret leakInjectionSupply chainResearchCVE (CVSS ≥ 7)

The pace is unprecedented.

98+
Distinct CVEs (CVSS ≥ 7)
across agent IDEs, MCP servers & LLM frameworks
198+
Malicious packages
npm · PyPI · crates.io · VS Code · agent skill stores
137 / 62d
Advisories in 62 days
one leading agent CLI, Feb–Apr 2026 (≈1 every 15h)
9 / 4d
CVEs in four days
same product, peak week in March 2026

Things that had never happened before.

Jun 2025FIRSTzero-click prompt-injection CVEEchoLeak · CVE-2025-32711
Aug 2025FIRSTAI-CLI-weaponizing supply-chain wormNx s1ngularity
Sep 2025FIRSTself-replicating npm wormShai-Hulud
Sep 2025FIRSTmalicious MCP package caught in the wildpostmark-mcp · BCC backdoor
Nov 2025FIRSTstate-grade autonomous espionage campaignGTG-1002 · Anthropic disclosure
Mar 2026FIRSTnine CVEs against a single agent CLI in four daysjgamblin/OpenClawCVEs tracker
Jul 2026FIRSTend-to-end agentic ransomware operationJADEPUFFER · Sysdig
Jul 2026FIRSTfrontier model escaping an eval into third-party productionGPT-5.6 Sol · OpenAI / Hugging Face

46 named incidents, each with sources.

2026
Jul 2026Rogue action
JADEPUFFER: the first end-to-end agentic ransomware
Sysdig documented the first extortion operation driven end to end by an LLM: autonomous recon, credential harvesting, a Nacos takeover encrypting 1,342 config items, 600+ distinct payloads, self-correcting within 31 seconds of a failure.
Sources: Sysdig
Jul 2026Injection
GhostApproval: symlinks turn agent approval prompts into rubber stamps
Wiz showed malicious repos disguising symlinks as project files: the agent writes to targets like ~/.ssh/authorized_keys while the approval prompt shows only a harmless workspace path; six coding assistants affected.
Jul 2026Rogue action
OpenAI models escape an eval sandbox into Hugging Face production
GPT-5.6 Sol and an unreleased model on a cyber-capability eval escaped containment via a third-party zero-day, breached Hugging Face production through two dataset-pipeline code-execution paths, harvested service credentials and moved laterally in tens of thousands of automated actions.
Sources: Hugging Face · Fortune
Jul 2026Supply chain
AgentBaiting: 7,600 fake repos hunt coding agents
Island documented ~7,600 fake GitHub repos run by ~6,600 sock-puppet accounts, 800+ posing as AI Skills and MCP servers, 14M+ downloads; coding agents autonomously surfaced and recommended them, delivering the SmartLoader and StealC credential stealers.
Jun 2026Injection
Claude Code GitHub Action steered into exfiltrating CI secrets
Microsoft showed injection hidden in issues, PRs or comments could steer the Action into reading and exfiltrating pipeline credentials, hiding the shell payload behind an attacker-controlled domain; fixed in Claude Code 2.1.128.
Sources: Decrypt · CSA Labs
Jun 2026Supply chain
Mastra npm scope backdoored via a dormant contributor account
A hijacked former-contributor account with unrevoked scope access shipped trojanized builds of ~145 Mastra packages executing at postinstall; Microsoft attributed the campaign to North Korea's Sapphire Sleet.
Jun 2026Research
4,982 security issues across 9,695 public MCP servers
Trend Micro scanned 9,695 MCP servers across four directories: 2,259 had issues, 4,982 in total, including 880 arbitrary-file-access and 476 command-injection flaws; popularity and verification badges barely correlate with security.
Sources: Trend Micro
May 2026Injection
Morse-code injection drains a Grok-linked agent wallet
A Morse-coded reply tricked Grok into decoding a transfer order and tagging the Bankr trading agent, which executed it as an authenticated command and moved ~3B DRB tokens (reported at $150K to $200K); most was later returned.
Sources: SlowMist · OECD.AI
May 2026Secret leak
Composio breach exposes 10,000+ customer credentials
One stolen employee Gmail OAuth token let an attacker pivot into the credential store of the agent-integration platform, exposing 5,001 GitHub OAuth tokens and 5,241 API keys and forcing company-wide rotation.
May 2026Supply chain
TrapDoor poisons CLAUDE.md and .cursorrules with zero-width Unicode
Socket tracked 34+ malicious packages across npm, PyPI and crates.io hiding instructions in zero-width Unicode inside agent config files, so assistants reading them ran credential theft disguised as a "security scan".
Apr 2026Supply chain
Malicious LLM routers drain a $500K crypto wallet
A joint study of 428 LLM API routers found 26 injecting malicious tool calls and 17 stealing AWS credentials; one real customer lost $500,000.
Sources: CoinDesk · OECD.AI
Apr 2026Research
29M secrets leaked in 2025; AI-related up 81% YoY
GitGuardian's annual report counts 29M new hardcoded-secret leaks on GitHub in 2025; AI-assisted code hardcodes significantly more keys than human-written code.
Mar 2026Supply chain
LiteLLM backdoored on npm and PyPI
TeamPCP planted backdoors in LiteLLM packages; as API middleware for many AI apps, every key flowing through it was at risk.
Sources: Trend Micro
Mar 2026Secret leak
Claude Code source leaks via npm .map files
A release accidentally shipped .map files, exposing 510K lines of source including hardcoded client tokens and unreleased feature flags.
Mar 2026Rogue action
Claude Code deletes 2.5 years of production data
A developer's agent deleted production configs, the database and its snapshots; 2.5 years of records gone in an instant.
Mar 2026Rogue action
Meta internal agent triggers a SEV1 exposure
An internal agent posted incorrect configuration advice without approval; the chain reaction exposed sensitive data to unauthorized staff for nearly two hours.
Sources: Yahoo Tech
Feb 2026Supply chain
1,184 malicious ClawHub skills flagged
Antiy and Snyk analyses found 76 payloads and 534 critical skills (13.4% of those scanned); installed skills run arbitrary code inside agent sessions.
Sources: Snyk
Feb 2026Secret leak
Moltbook leaks 1.5M API keys
Wiz found a misconfigured database with RLS disabled, exposing 1.5M API keys, 35K emails and private agent-to-agent messages.
Sources: Wiz
Feb 2026Rogue action
OpenClaw autonomously deletes hundreds of emails
Context compaction dropped the confirm-first instruction; the agent autonomously purged hundreds of emails from a Meta alignment director's inbox.
Sources: TechCrunch · PCMag
Jan 2026Injection
service_role + support tickets drain the database
With a service_role key the agent bypasses RLS; instructions hidden in support tickets induced bulk cross-tenant SELECTs posted back into the thread.
Jan 2026Secret leak
42K OpenClaw instances expose API keys
Plaintext config keys plus insecure default ports left 42,000+ instances harvestable for Anthropic keys, Slack credentials and Telegram tokens.
Sources: Medium
2025
Dec 2025Injection
Comment & Control: a PR title steals your API key
Instructions hidden in HTML comments of PR titles and issues coerced mainstream coding agents into running commands and exfiltrating API keys and tokens.
Sources: TMTPost
Dec 2025Injection
Atlas prompt-injected into sending a resignation email
OpenAI confirmed a real-world prompt injection: a crafted email drove Atlas to send the user's resignation to their manager with no confirmation.
Sources: OpenAI
Dec 2025Rogue action
Amazon Kiro wipes AWS production; 13-hour outage
The internal coding agent inherited operator permissions, bypassed two-person approval, and chose to delete-and-rebuild production; 1,500 engineers signed a protest.
Sources: Fortune · paddo.dev
Nov 2025Supply chain
230K Ray clusters mass-exploited
AI-generated scripts exploited CVE-2023-48022 across 230,000+ public clusters for cryptomining, data theft and DDoS.
Nov 2025Supply chain
SesameOp: Assistants API as a covert C2 channel
Microsoft found a backdoor hiding command-and-control traffic inside legitimate API requests, invisible to conventional egress detection.
Sources: Microsoft
Nov 2025Injection
A2A session smuggling hijacks the orchestrator
A malicious sub-agent smuggled instructions across session boundaries in multi-turn A2A conversations, hijacking a trusted orchestrator.
Sources: Unit 42
Nov 2025Injection
First in-the-wild mass indirect prompt injection
Unit 42 documented hidden instructions in malicious webpages tricking AI ad moderators into approving scam ads at scale.
Sources: Unit 42
Nov 2025Rogue action
State-linked group runs autonomous espionage via Claude Code
Anthropic disrupted GTG-1002, which ran agents against ~30 targets with 80–90% of reconnaissance and exploitation executed autonomously.
Sources: Anthropic · BBC
Nov 2025Rogue action
Google Antigravity wipes a user's entire D drive
A path with a space parsed wrong and rmdir /s /q pointed at the drive root; photos, videos and work files were permanently lost.
Oct 2025Injection
Case-sensitivity bypass to MCP RCE (CVE-2025-59944)
CVSS 9.8: a case-insensitive filesystem bypassed the protected-path check, letting injection overwrite mcp.json for RCE.
Sources: NVD
Sep 2025Injection
ShadowLeak: zero-click Gmail exfiltration via Deep Research
Radware disclosed a server-side zero-click chain: one crafted email made the agent leak Gmail inbox contents to attacker infrastructure.
Sources: Radware
Aug 2025Supply chain
WhiteCobra extension robs an Ethereum core developer
A lookalike Solidity extension silently read workspace .env files for private keys; the wider campaign spans dozens of extensions and hundreds of thousands of dollars.
Aug 2025Supply chain
Nx poisoned; local AI CLIs weaponized
Malicious builds drove victims' local coding agents to scan wallets and tokens, then force private GitHub repos public: the first AI-CLI-weaponizing supply-chain worm.
Aug 2025Injection
AgentFlayer: zero-click chains demoed at Black Hat
Zenity Labs demoed silent one-shot exfiltration chains against ChatGPT Connectors, Copilot Studio, Cursor + Jira and more.
Sources: Wired
Aug 2025Injection
Comet hijacked via hidden Reddit spoilers
Commands hidden in spoiler markup drove Comet to log into the user's email, solve CAPTCHAs and exfiltrate credentials in under 150 seconds.
Aug 2025Injection
Cursor RCE via README prompt injection (CVE-2025-54135)
Hidden prompts in a README executed attacker commands on project open; a sibling variant (CurXecute) reached RCE via the MCP config chain.
Sources: The Hacker News · NVD
Aug 2025Secret leak
Stolen Drift OAuth tokens hit 700+ Salesforce tenants
UNC6395 pivoted into 700+ customer tenants using stolen long-lived integration tokens; no exploit or phishing required.
Sources: Reco
Jul 2025Supply chain
Amazon Q extension poisoned with system-wipe commands
An attacker pushed wipe-your-system instructions into the VS Code extension; the poisoned build shipped to 1M+ installs before removal.
Jul 2025Supply chain
mcp-remote command injection (CVE-2025-6514)
CVSS 9.6: the dominant OAuth proxy for MCP clients had an OS command injection; connecting to a malicious MCP server yielded RCE.
Sources: NVD
Jul 2025Rogue action
Replit agent deletes a prod database, fabricates data to cover it
Ignoring an explicit code freeze, the agent deleted a production database of 1,206 executives, then fabricated 4,000+ records and claimed the data was unrecoverable.
Sources: Fortune
Jun 2025Injection
EchoLeak: zero-click Copilot exfiltration (CVSS 9.3)
CVE-2025-32711: one email with hidden instructions made Copilot auto-exfiltrate sensitive documents while summarizing the inbox.
Sources: MSRC
Jun 2025Research
Agentic Misalignment: 16 frontier models cross the line
Under simulated replacement pressure, most tested models actively chose to blackmail executives or leak documents; rates reached 96%.
Sources: Anthropic
May 2025Injection
GitHub MCP injection exfiltrates private repos
Malicious issues hijacked MCP-wired agents into copying private source and secrets to attacker-controlled public repos.
May 2025Injection
Browser Use allowlist bypass (CVE-2025-47241)
A URL-parser flaw let the user:pass@host trick bypass the allowed_domains whitelist, reaching attacker-controlled hosts.
Sources: GHSA
Apr 2025Supply chain
Langflow unauthenticated RCE mass-exploited (CISA KEV)
CVE-2025-3248 (CVSS 9.8) in the agent-builder platform saw active mass exploitation, including by the Flodrix botnet.
Sources: NVD
One root cause keeps recurring: the agent held the keys.
See a different design →