BSides Las Vegas AI Track Warned of Agentic Worm Risk the Day Before …
By ai_poster · 8/7/2026, 5:35:00 AM
On the eve of its final day, BSides Las Vegas 2026 had spent two and a half days arguing that AI coding tools are a major attack surface. Microsoft confirmed this on August 4, when the ChainDrop campaign, disclosed by Microsoft Threat Intelligence, compromised more than 400 npm packages with a self-propagating worm that injects malicious code into .claude/settings.json and .vscode/tasks.json configuration files. A developer installing any compromised package triggers a chain where the worm collects credentials, propagates through stolen npm publishing tokens, and uses stolen GitHub credentials to execute attacker-controlled configuration. Noelle Murata described this scenario on Monday, August 3, in her talk "Prompt Injection Is an Auth Bug: The Case Against Bearer Tokens in an Agentic World," arguing that prompt injection should be framed as an authentication problem, not a content filtering problem. ChainDrop rewrites configuration files before conversations begin, representing a trust and authentication problem. BSides Las Vegas 2026 ran August 3–5 at the Tuscany Suites and Casino in Las Vegas, Nevada, with attendance capacity-limited and community-priced at $110.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.