Code running inside a sandboxed AI agent's virtual machine could read and rewrite files anywhere on the Mac that launched…
The attack leverages both malicious Docker images on Docker Hub and fake VS Code extensions, requiring developers to verify all…