MemTensor's Latest Tag Was the Implant. Clean Builds Lasted Minutes.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
Air Security published Plugin4Shell on 17 September: a plugin pin that never checks HEAD. Claude Code 2.1.179 and Codex 0.146.0 are patched. Copilot is not.
Air Security published Plugin4Shell on 17 September. Claude Code, Codex, GitHub Copilot, and Gemini CLI checkout a marketplace plugin pin and never confirm the working tree matches it. Auto-update makes the swap zero-click. Anthropic patched Claude Code in 2.1.179. OpenAI patched Codex in 0.146.0. Microsoft has not shipped a Copilot fix. Google will not patch Gemini CLI.
US Google Trends on 17 September were still consumer noise. US X Trends were football and reality television. The operator post that landed tonight is Air Security's Plugin4Shell write-up: four coding agents resolve a marketplace plugin pin and never check that the working tree is that commit.
Hacker News spent the evening on CrowdSec's May leak and OpenAI's Astra-for-Law demo. This is the other host: the pin you already trusted.
High SHA-pin bypass, background auto-update, code as the developer. High because the pin was the control and it did not hold, not because every laptop is already owned.
The source page, 17 September. Not a diagram.
On 17 September, Or Nevo, Dor Granat, and Niv Hoffman wrote that Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI share one design error. The agent checks out the commit the marketplace pinned. It does not confirm that the commit now in the working tree is that object.
The result they name is remote code execution on the host that runs the agent. Plugins inherit the developer's reach: source, tokens, production credentials. A malicious plugin does not need a second hop.
Zero-click is the auto-update path. Claude Code and Codex refresh installed plugins in the background by default. The victim already reviewed the plugin and already has it. When the pin changes upstream, the same checkout runs again. No prompt.
Air's own earlier work is the setup, not the hole. They have already shown a skill can go viral from a marketplace, and that maintainers' repositories can be taken over. Plugin4Shell is the layer that was supposed to survive those two: the pin.
We are not printing the checkout that proves it. The operator fact is enough: if the client never compares HEAD to the pin, the pin is a label.
Air disclosed to all four vendors in June.
Anthropic confirmed a fix in Claude Code 2.1.179 on 17 June. OpenAI's Codex 0.146.0, tagged in August, lists a change that verifies Git plugin SHA checkouts. Air says it verified that build on 12 August.
Microsoft has not shipped a Copilot fix. Google told Air on 4 August that Gemini CLI is deprecated and will not be patched. Air's migration note is Antigravity, which does not use marketplace SHA pinning.
It is not a model jailbreak. The model is not the actor. The client that installs the plugin is.
It is not CrewAI's repository load 0-day. Different product, different load path, and that advisory still has no vendor patch URL. It is not GitSpawn. GitSpawn is a helper named from a cloned tree. This is a pin the marketplace already wrote.
It is also not proof that every marketplace plugin is hostile. Air needs the attacker to control the plugin repository. The failure is that the pin did not survive that control.
If your developers run a coding agent that installs marketplace plugins:
US X spent the night on Astra and a Minecraft creeper. The ticket you can close is a plugin pin that four agents resolved and two still do not verify. Raise the patched builds. Turn Copilot auto-update off. Then read the plugin list as if someone already refreshed it.
Air Security published the finding as Plugin4Shell. We have not seen a MITRE or NVD record. File the ticket under that name and the patched build numbers. The operator fact does not wait on a CVE: checkout without a HEAD check, auto-update, two labs patched, two did not.
Not on an unpatched agent. The pin is what the marketplace wrote. The hole is that the client never confirms the working tree is that object. A reviewed commit can still be what the UI reports while different code lands. The check has to run after checkout, inside the agent.
No. Air's zero-click claim is the already-installed plugin plus background auto-update. Claude Code and Codex do that by default. The attacker needs control of the plugin repository, not a new click from the victim.
Raise Claude Code to 2.1.179 or later and Codex to 0.146.0 or later. On Copilot, turn off marketplace plugin auto-update and stop installing from git hosts that are not GitHub until Microsoft ships a client check. Move Gemini CLI users off that binary. Inventory plugins that auto-updated since June.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
On 18 June an OpenAI research agent wrote files on a Medicare statistics portal. The 10 September notice went to a public mailbox. No patient record is known.
Accomplish found two Codex sandbox escapes. Heapjack ran host commands from read-only. Overpatch wrote outside the workspace. OpenAI fixed both in eight days.