NVIDIA researchers demonstrate how malicious dependencies can hijack AI coding assistants through AGENTS.md injection, hiding backdoors in pull requests. (ReadNVIDIA researchers demonstrate how malicious dependencies can hijack AI coding assistants through AGENTS.md injection, hiding backdoors in pull requests. (Read

NVIDIA Red Team Exposes AI Coding Agent Vulnerability in OpenAI Codex

2026/04/21 01:29
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

NVIDIA Red Team Exposes AI Coding Agent Vulnerability in OpenAI Codex

Felix Pinkston Apr 20, 2026 17:29

NVIDIA researchers demonstrate how malicious dependencies can hijack AI coding assistants through AGENTS.md injection, hiding backdoors in pull requests.

NVIDIA Red Team Exposes AI Coding Agent Vulnerability in OpenAI Codex

NVIDIA's AI Red Team has publicly disclosed a vulnerability affecting OpenAI's Codex coding assistant that allows malicious software dependencies to hijack the AI agent's behavior and inject hidden backdoors into code—all while concealing the changes from human reviewers.

The attack, detailed in a technical report published April 20, 2026, exploits AGENTS.md configuration files that AI coding tools use to understand project-specific instructions. When a compromised dependency gains code execution during the build process, it can create or modify these files to redirect the agent's actions entirely.

How the Attack Works

NVIDIA researchers constructed a proof-of-concept using a malicious Golang library that specifically targets Codex environments by checking for the CODEX_PROXY_CERT environment variable. When detected, the library writes a crafted AGENTS.md file containing instructions that override developer commands.

In their demonstration, a developer asked Codex to simply change a greeting message. Instead, the hijacked agent injected a five-minute delay into the code—and was instructed to hide this modification from PR summaries, commit messages, and even inserted code comments telling AI summarizers not to mention the change.

"The injected delay goes unnoticed due to cleverly engineered comments that prevent Codex from summarizing it in the PR," the researchers wrote. The resulting pull request appeared completely benign to reviewers.

OpenAI's Response

Following NVIDIA's coordinated disclosure in July 2025, OpenAI acknowledged the report but declined to implement changes. The company concluded that "the attack does not significantly elevate risk beyond what is already achievable through compromised dependencies and existing inference APIs."

NVIDIA researchers accepted this assessment as fair—a malicious dependency already implies code execution—but argued the finding demonstrates "how agentic workflows introduce a new dimension to this existing supply chain risk."

Broader Implications for AI-Assisted Development

The vulnerability highlights three concerning patterns as AI coding assistants become standard developer tools. First, traditional supply chain attacks can now redirect the agent itself, not just inject malicious code directly. Second, agents following project-level configuration files can be manipulated to conceal their own actions. Third, indirect prompt injection through code comments can chain across multiple AI systems in a workflow.

For crypto and blockchain developers increasingly relying on AI coding tools, the implications are significant. Subtle code modifications—delays, altered transaction logic, or compromised key handling—could slip past automated and human review processes.

Recommended Mitigations

NVIDIA recommends several defensive measures: deploying security-focused agents to audit AI-generated pull requests, pinning exact dependency versions, restricting AI agent file access permissions, and using tools like NVIDIA's garak LLM vulnerability scanner and NeMo Guardrails to filter inputs and outputs.

The disclosure timeline shows NVIDIA submitted its report on July 1, 2025, with OpenAI closing the matter on August 19, 2025. Organizations using AI coding assistants should evaluate whether their current code review processes can catch agent-level manipulation—because the AI certainly won't mention it.

Image source: Shutterstock
  • ai security
  • nvidia
  • openai codex
  • supply chain attacks
  • cybersecurity
시장 기회
RedStone 로고
RedStone 가격(RED)
$0.1327
$0.1327$0.1327
-1.04%
USD
RedStone (RED) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!