HookPry Trojanizes Seven AI Agent Harnesses Through Lifecycle-Hook Updates, With 0% Recall From Microsoft Defender
Researchers identify the lifecycle-hook update path as a new supply-chain attack surface: harnesses bind shell commands to events like session start, tool calls and file edits, run them with host privileges, and trust plugin update metadata blindly, so a benign versioned plugin can be trojanized to fire attacker-chosen commands the LLM never observes. HookPry, an open-source automated attack framework realizing ten attack objectives, compromised all seven evaluated harnesses across 25 harness-backend combinations in 1,000 end-to-end runs, with per-harness success reaching 92.5%. Microsoft Defender had 0% recall and the union of three static defenses missed 47.5% of malicious artifacts, which means anyone running hook configs from a versioned plugin should be diffing the hook block on every update rather than relying on endpoint scanning.
↳ Follow the thread