An npm Package Hardcoded the Path Where Your AI Coding Agent Stores Files. That String Is the New ~/.aws/credentials.
technical
8 min read

An npm Package Hardcoded the Path Where Your AI Coding Agent Stores Files. That String Is the New ~/.aws/credentials.

A clumsy AI-built npm package exfiltrated files from the standardized agent workspace directory and still reached 676 downloads. The path is a named target now, and most security teams have not inventoried it.

Harper Foley

Harper Foley

General Manager at Tribe AI. Former Navy EOD.

Share