A new analysis at rushter.com documents the systematic rise of malicious repositories on GitHub engineered to compromise developers who rely on package and library discovery during AI-assisted coding sessions. The attack surface is acutely elevated for vibe coding and agentic workflows where agents autonomously install dependencies without manual review of repository provenance. With 518 upvotes on r/programming and 74 comments, this is a high-signal supply chain warning for teams running autonomous coding agents with write access to dependency files.