The pin was supposed to freeze the plugin. The agents never checked that the checkout actually landed on that pin.
On September 17, 2026, Air Security researchers Or Nevo, Dor Granat, and Niv Hoffman published Plugin4Shell: a plugin SHA-pinning bypass that yields zero-click remote code execution on the major AI coding agents — Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The Register covered the disclosure the same day. This read rests on the primary Air write-up and The Register’s vendor statements; agent and Fortune-500 counts are Undisclosed.
What fails: agents clone a marketplace plugin and git checkout the pinned SHA, but do not verify that HEAD equals that SHA after checkout. An attacker who controls the plugin repo can create a branch whose name is the 40-hex pin (or, for Gemini CLI’s FETCH_HEAD path, a default branch named FETCH_HEAD) so git resolves a ref instead of the commit. The pin still “looks” honored. Marketplace review does not close it — the pin is resolved inside the agent.
Why zero-click: Claude Code and Codex auto-update installed plugins in the background by default. When a pin bumps and the upstream rug-pull is in place, already-installed plugins swap to attacker code with no install prompt. Air describes two paths: publish a benign plugin then rug-pull, or hijack a trusted author’s repo (their earlier SkillJacking / RepoJacking demos) and force the malicious pin onto every agent that already has it.
Patches (Air timeline + Register): found May 2026; coordinated disclosure to all four vendors June 2026. Claude Code 2.1.179 fixed (Anthropic confirmed 2026-06-17). Codex 0.146.0 fixed (verified 2026-08-12). Gemini CLI: Google confirmed no fix — product deprecated; migrate to Antigravity, which Air says this attack does not reach. GitHub Copilot: Air says Microsoft has not shipped an agent-side fix. A GitHub spokesperson told The Register that GitHub blocks branch/tag names that resemble commit SHAs, so the attack “cannot be exploited on GitHub.” Air’s reply: marketplaces on Bitbucket and self-hosted git are supported backends, so Copilot remains exposed where those hosts allow SHA-shaped branch names. Redmond had not responded to The Register at publication.
Counts: Air frames reach as “millions of agents” and marketplace installs, which is researcher framing. Confirmed agent/install totals: Undisclosed. The Register cites Microsoft’s claim that almost 90% of Fortune 500 companies use Copilot; that is Microsoft’s figure via The Register, not a Plugin4Shell victim tally.
POV: AI coding agents inherit the employee’s keys to the kingdom. SHA pinning was the industry’s answer to SkillJacking-style rug-pulls; Plugin4Shell shows the pin without a post-checkout equality check is theater. Update Claude Code and Codex now. Do not treat “GitHub blocks SHA branch names” as a Copilot all-clear if Bitbucket/self-hosted marketplaces are in play. Gemini CLI users: migrate. Sources: Air Sep 17 and The Register Sep 17.
