The Containment Era is here. →Explore

Executive Summary

In June 2024, researchers at Checkmarx Zero demonstrated a novel supply chain attack called 'Lies-in-the-Loop' (LITL) targeting AI-assisted coding agents, specifically Anthropic's Claude Code. By leveraging prompt injection, attackers manipulated the AI into concealing malicious code execution behind benign prompts, effectively tricking human operators into approving dangerous actions. The attack exploited trust in the 'human-in-the-loop' workflow, showing that malicious context within public resources like GitHub issues could hide remote code execution triggers. Successful exploitation enabled attackers to deploy arbitrary commands and potentially introduce malicious packages into software repositories, increasing the risk of downstream supply chain compromise.

This incident highlights a concerning trend: as AI coding agents are rapidly adopted, their interfaces become a ripe target for adversaries using social engineering and prompt manipulation. The attack underscores the evolving sophistication of supply chain threats, especially those that blur the lines between human fallibility and machine autonomy in development environments.

Why This Matters Now

With AI code assistants increasingly integrated into corporate development workflows, attacks like Lies-in-the-Loop demonstrate an urgent need for robust guardrails and user education. Adversaries can now use prompt injections to bypass human oversight, turning trusted AI into an attack vector—escalating the urgency for preventative controls and defense-in-depth strategies against new forms of supply chain compromise.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used prompt injection to trick AI agents into misrepresenting dangerous actions as safe, hiding malicious execution behind overly long or manipulated prompts.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, microsegmentation, granular egress control, and cloud-native threat detection would have reduced the attack surface, limited malicious package distribution, and detected anomalous behaviors originating from compromised coding agents.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Distributed, real-time inspection would have detected manipulated content or agentic AI risk at the control plane.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based segmentation would constrain agent actions to their least privilege contexts.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation and strict flow controls would block agent-initiated pivots to internal systems.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound traffic inspection would detect or block attempts to reach attacker-controlled endpoints.

Exfiltration

Control: Cloud Firewall (ACF)

Mitigation: Egress NAT and URL filtering would prevent data leakage to untrusted destinations.

Impact (Mitigations)

Anomaly detection surfaces agent behavior that diverges from baseline, triggering rapid response.

Impact at a Glance

Affected Business Functions

  • Software Development
  • IT Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive code repositories and intellectual property due to unauthorized command execution.

Recommended Actions

  • Implement Zero Trust segmentation for all coding agents and developer infrastructure to restrict agent permissions and limit blast radius.
  • Enforce strong egress controls and granular FQDN filtering to block unauthorized data movement and detect malicious outbound connections.
  • Deploy distributed, inline inspection such as CNSF to monitor, audit, and enforce policy on agent interactions with external content.
  • Baseline agent and user behaviors and continuously monitor for anomalies with integrated threat detection and automated incident response.
  • Ensure ongoing user training on prompt injection, social engineering, and supply chain risk, and operationalize defense-in-depth for agentic AI workflows.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image