Vibe CodingClinejection Supply Chain Attack Analysis by Willison and SnykSimon Willison·high signalXBlueskyLinkedInCopy linkPrompt injection in GitHub issue title compromised Cline npm publishing tokens via cache poisoning. 4000 developer machines affected in 8-hour window.SourceSource pageSimon Willison↳ Follow the threadPolicy dependency / Stack layer'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security directorr/ClaudeAIThreat pattern / Update threadDatasette ships 1.0a40 and a 0.65.5 security fix, with background task support for pluginsSimon WillisonStack layer / Threat patternEmergence World ran 10 agents per world for 16 days and found no frontier model contained an injected attack — one acted on poisoned memory 46 hours laterarXivPolicy dependency / Stack layerCodex makes Code Mode wrappers transparent to Guardian policy and adds read-only policy to MCP tool requestsGitHubStack layer / Threat patternTwo Tool-Level Defenses Drive Prompt Injection and Memory Poisoning to 0% Attack Success in Many SettingsarXiv 2609.16098Stack layer / Threat patternDeepSeek V4.1 Flash Popped All 11 Vulnerable Targets in Enclave's Offensive Security Benchmark for $5.14Enclave (model release corroborated by DeepSeek) / Hacker News (167pts, 66 comments)Stack layer / Threat patternCline's compaction trigger was estimating tokens at 3 characters each and never firing on dense contentGitHubStack layer / Threat patternThree new advisories land on the most-used community GitLab MCP server, including a five-way bypass of its read-only mode and project allow-listGitHub Advisory Database