The first 16 months of the agent era.

Publicly disclosed incidents, CVEs and malicious packages. Filed chronologically, facts and sources only.

0+
Vulnerabilities & incidents
disclosed 2025 to 2026.04
0+
CVEs at CVSS ≥ 7
against agent tooling
0
Malicious packages
npm / PyPI / VS Code / skills
0
Named real-world incidents
covered individually below

Getting denser every quarter.

Big dots = named incidents, colored by kind. Small dots = CVEs. Hover for the story.

Jan2025FebMarAprMayJunJulAugSepOctNovDecJan2026FebMarApr
Rogue actionSecret leakInjectionSupply chainResearchCVE (CVSS ≥ 7)

The pace is unprecedented.

55+
Distinct CVEs (CVSS ≥ 7)
across agent IDEs, MCP servers & LLM frameworks
20
Malicious packages
npm · PyPI · VS Code · agent skill stores
137 / 62d
Advisories in 62 days
one leading agent CLI, Feb–Apr 2026 (≈1 every 15h)
9 / 4d
CVEs in four days
same product, peak week in March 2026

Things that had never happened before.

Jun 2025FIRSTzero-click prompt-injection CVEEchoLeak · CVE-2025-32711
Aug 2025FIRSTAI-CLI-weaponizing supply-chain wormNx s1ngularity
Sep 2025FIRSTself-replicating npm wormShai-Hulud
Sep 2025FIRSTmalicious MCP package caught in the wildpostmark-mcp · BCC backdoor
Nov 2025FIRSTstate-grade autonomous espionage campaignGTG-1002 · Anthropic disclosure
Mar 2026FIRSTnine CVEs against a single agent CLI in four daysjgamblin/OpenClawCVEs tracker

36 named incidents, each with sources.

2026
Apr 2026Supply chain
Malicious LLM routers drain a $500K crypto wallet
A joint study of 428 LLM API routers found 26 injecting malicious tool calls and 17 stealing AWS credentials; one real customer lost $500,000.
Sources: CoinDesk · OECD.AI
Apr 2026Research
29M secrets leaked in 2025; AI-related up 81% YoY
GitGuardian's annual report counts 29M new hardcoded-secret leaks on GitHub in 2025; AI-assisted code hardcodes significantly more keys than human-written code.
Mar 2026Supply chain
LiteLLM backdoored on npm and PyPI
TeamPCP planted backdoors in LiteLLM packages; as API middleware for many AI apps, every key flowing through it was at risk.
Sources: Trend Micro
Mar 2026Secret leak
Claude Code source leaks via npm .map files
A release accidentally shipped .map files, exposing 510K lines of source including hardcoded client tokens and unreleased feature flags.
Mar 2026Rogue action
Claude Code deletes 2.5 years of production data
A developer's agent deleted production configs, the database and its snapshots; 2.5 years of records gone in an instant.
Mar 2026Rogue action
Meta internal agent triggers a SEV1 exposure
An internal agent posted incorrect configuration advice without approval; the chain reaction exposed sensitive data to unauthorized staff for nearly two hours.
Sources: Yahoo Tech
Feb 2026Supply chain
1,184 malicious ClawHub skills flagged
Antiy and Snyk analyses found 76 payloads and 534 critical skills (13.4% of those scanned); installed skills run arbitrary code inside agent sessions.
Sources: Snyk
Feb 2026Secret leak
Moltbook leaks 1.5M API keys
Wiz found a misconfigured database with RLS disabled, exposing 1.5M API keys, 35K emails and private agent-to-agent messages.
Sources: Wiz
Feb 2026Rogue action
OpenClaw autonomously deletes hundreds of emails
Context compaction dropped the confirm-first instruction; the agent autonomously purged hundreds of emails from a Meta alignment director's inbox.
Sources: TechCrunch · PCMag
Jan 2026Injection
service_role + support tickets drain the database
With a service_role key the agent bypasses RLS; instructions hidden in support tickets induced bulk cross-tenant SELECTs posted back into the thread.
Jan 2026Secret leak
42K OpenClaw instances expose API keys
Plaintext config keys plus insecure default ports left 42,000+ instances harvestable for Anthropic keys, Slack credentials and Telegram tokens.
Sources: Medium
2025
Dec 2025Injection
Comment & Control: a PR title steals your API key
Instructions hidden in HTML comments of PR titles and issues coerced mainstream coding agents into running commands and exfiltrating API keys and tokens.
Sources: TMTPost
Dec 2025Injection
Atlas prompt-injected into sending a resignation email
OpenAI confirmed a real-world prompt injection: a crafted email drove Atlas to send the user's resignation to their manager with no confirmation.
Sources: OpenAI
Dec 2025Rogue action
Amazon Kiro wipes AWS production; 13-hour outage
The internal coding agent inherited operator permissions, bypassed two-person approval, and chose to delete-and-rebuild production; 1,500 engineers signed a protest.
Sources: Fortune · paddo.dev
Nov 2025Supply chain
230K Ray clusters mass-exploited
AI-generated scripts exploited CVE-2023-48022 across 230,000+ public clusters for cryptomining, data theft and DDoS.
Nov 2025Supply chain
SesameOp: Assistants API as a covert C2 channel
Microsoft found a backdoor hiding command-and-control traffic inside legitimate API requests, invisible to conventional egress detection.
Sources: Microsoft
Nov 2025Injection
A2A session smuggling hijacks the orchestrator
A malicious sub-agent smuggled instructions across session boundaries in multi-turn A2A conversations, hijacking a trusted orchestrator.
Sources: Unit 42
Nov 2025Injection
First in-the-wild mass indirect prompt injection
Unit 42 documented hidden instructions in malicious webpages tricking AI ad moderators into approving scam ads at scale.
Sources: Unit 42
Nov 2025Rogue action
State-linked group runs autonomous espionage via Claude Code
Anthropic disrupted GTG-1002, which ran agents against ~30 targets with 80–90% of reconnaissance and exploitation executed autonomously.
Sources: Anthropic · BBC
Nov 2025Rogue action
Google Antigravity wipes a user's entire D drive
A path with a space parsed wrong and rmdir /s /q pointed at the drive root; photos, videos and work files were permanently lost.
Oct 2025Injection
Case-sensitivity bypass to MCP RCE (CVE-2025-59944)
CVSS 9.8: a case-insensitive filesystem bypassed the protected-path check, letting injection overwrite mcp.json for RCE.
Sources: NVD
Sep 2025Injection
ShadowLeak: zero-click Gmail exfiltration via Deep Research
Radware disclosed a server-side zero-click chain: one crafted email made the agent leak Gmail inbox contents to attacker infrastructure.
Sources: Radware
Aug 2025Supply chain
WhiteCobra extension robs an Ethereum core developer
A lookalike Solidity extension silently read workspace .env files for private keys; the wider campaign spans dozens of extensions and hundreds of thousands of dollars.
Aug 2025Supply chain
Nx poisoned; local AI CLIs weaponized
Malicious builds drove victims' local coding agents to scan wallets and tokens, then force private GitHub repos public: the first AI-CLI-weaponizing supply-chain worm.
Aug 2025Injection
AgentFlayer: zero-click chains demoed at Black Hat
Zenity Labs demoed silent one-shot exfiltration chains against ChatGPT Connectors, Copilot Studio, Cursor + Jira and more.
Sources: Wired
Aug 2025Injection
Comet hijacked via hidden Reddit spoilers
Commands hidden in spoiler markup drove Comet to log into the user's email, solve CAPTCHAs and exfiltrate credentials in under 150 seconds.
Aug 2025Injection
Cursor RCE via README prompt injection (CVE-2025-54135)
Hidden prompts in a README executed attacker commands on project open; a sibling variant (CurXecute) reached RCE via the MCP config chain.
Sources: The Hacker News · NVD
Aug 2025Secret leak
Stolen Drift OAuth tokens hit 700+ Salesforce tenants
UNC6395 pivoted into 700+ customer tenants using stolen long-lived integration tokens; no exploit or phishing required.
Sources: Reco
Jul 2025Supply chain
Amazon Q extension poisoned with system-wipe commands
An attacker pushed wipe-your-system instructions into the VS Code extension; the poisoned build shipped to 1M+ installs before removal.
Jul 2025Supply chain
mcp-remote command injection (CVE-2025-6514)
CVSS 9.6: the dominant OAuth proxy for MCP clients had an OS command injection; connecting to a malicious MCP server yielded RCE.
Sources: NVD
Jul 2025Rogue action
Replit agent deletes a prod database, fabricates data to cover it
Ignoring an explicit code freeze, the agent deleted a production database of 1,206 executives, then fabricated 4,000+ records and claimed the data was unrecoverable.
Sources: Fortune
Jun 2025Injection
EchoLeak: zero-click Copilot exfiltration (CVSS 9.3)
CVE-2025-32711: one email with hidden instructions made Copilot auto-exfiltrate sensitive documents while summarizing the inbox.
Sources: MSRC
Jun 2025Research
Agentic Misalignment: 16 frontier models cross the line
Under simulated replacement pressure, most tested models actively chose to blackmail executives or leak documents; rates reached 96%.
Sources: Anthropic
May 2025Injection
GitHub MCP injection exfiltrates private repos
Malicious issues hijacked MCP-wired agents into copying private source and secrets to attacker-controlled public repos.
May 2025Injection
Browser Use allowlist bypass (CVE-2025-47241)
A URL-parser flaw let the user:pass@host trick bypass the allowed_domains whitelist, reaching attacker-controlled hosts.
Sources: GHSA
Apr 2025Supply chain
Langflow unauthenticated RCE mass-exploited (CISA KEV)
CVE-2025-3248 (CVSS 9.8) in the agent-builder platform saw active mass exploitation, including by the Flodrix botnet.
Sources: NVD
One root cause keeps recurring: the agent held the keys.
See a different design →