Plugin4Shell could widen exposure to enterprise systems

That gap, coupled with the likelihood that enterprises running affected coding agents are yet to patch or update them, could leave development environments exposed to attacks through compromised plugins, according to Pareekh Jain, principal analyst at Pareekh Consulting.

“Enterprises using AI coding agents with third-party plugins are likely to be most exposed, especially when those agents have access to source code, credentials, cloud systems or CI/CD tools as these plugins mostly run with the same access the developer or employee has,” he said.

That means that these malicious plugins could help attackers access source code, steal API keys or cloud credentials, change repositories, or potentially reach CI/CD and other corporate systems, Jain added.