← April 9, 2026 briefingTech
Self-replicating AI agent virus found in open source repo
Security researchers have discovered a self-replicating malicious payload embedded in a GitHub repository posing as an open-source coordination protocol for AI coding agents. When an AI agent reads the repository, it receives hidden instructions to embed the same payload into all future code it generates — spreading the infection to every subsequent agent that reads that code. The repository had only 10 stars and 1 fork, suggesting targeted rather than broad distribution.




