Attackers are using AI tools already installed on developer machines by delivering payloads as prompts in markdown files, bypassing traditional EDR tooling entirely.
Snapshot · The a16z Show
Attackers are using AI tools already installed on developer machines by delivering payloads as prompts in markdown files, bypassing traditional EDR tooling entirely.
Where this was said
At 13:40 · chapter starts 12:12
The episode's most cinematic moment: Joel de la Garza asks whether an active npm breach he'd heard about is still ongoing. Feross confirms — it's not one repo, it's hundreds. It's a worm. This is the concept the security community had theorized in blog posts for years: backdoor a package, use stolen developer credentials during installation to self-propagate, repeat. Someone finally actually did it, almost certainly using AI tools to write the malware. The threat group even open-sourced their vibe-coded toolkit, and copycat attacks have followed. But the story doesn't end with the worm itself. Feross describes a novel attack layer that is genuinely alarming: attackers are now delivering payloads as prompts inside markdown files, which are then executed silently by local AI CLI tools already running on developer machines. To an EDR system, this looks like a developer normally prompting Claude. Nothing is flagged. The AI searches the filesystem for credentials and exfiltrates them without a trace. [1] — Feross Aboukhadijeh "While recording this episode at Black Hat 2026, an npm worm was actively spreading across hundreds of repositories. The attack, likely vibe…" 12:12 [2] — Feross Aboukhadijeh "Attackers are hijacking AI tools already installed on developer machines by delivering payloads as prompts inside markdown files. To EDR so…" 13:30
During the Black Hat conference recording, an active npm worm was spreading across a few hundred repositories, with a maintainer whose insecure GitHub Action was likely the entry point.
While recording this episode at Black Hat 2026, an npm worm was actively spreading across hundreds of repositories. The attack, likely vibe-coded by the threat group that open-sourced their toolkit, exploited an insecure GitHub Action to steal tokens and self-propagate — a scenario the security community had theorized but never seen at scale.
Attackers are hijacking AI tools already installed on developer machines by delivering payloads as prompts inside markdown files. To EDR software, this looks like a developer normally prompting Claude. The AI then silently searches the filesystem for credentials and exfiltrates them — invisible to traditional security tooling.
Sam's initial MVP was coded in approximately one week using ChatGPT voice mode and copy-pasting code, with no prior technical experience.
Sam argues Discord is 10x better than email for building relationships with younger users who rarely check their inbox.
Sam's monthly operating costs include Cursor ($200), AI image generation ($100), AI video generation ($200), hosting ($100), email marketing ($80), and AI compute ($300–$500).
Sam recommends copying days of Discord chat history into ChatGPT and prompting it to list recurring pain points as a fast, free market research technique.
Bhanu and his team built approximately 50 free tools to attract search traffic, each linked back to SiteGPT.
With AI coding tools like Cursor, Bhanu can now create a new free marketing tool in less than 5 minutes by referencing existing tools.
Bhanu filters Ahrefs keyword results to show only those with a keyword difficulty below 10, making them realistic ranking targets for any decent website.
Bhanu sets a minimum search volume of 1,000 monthly searches when selecting keywords to target with free tools.
PropGPT averaged 20 downloads per day right after launching on the App Store through influencer marketing.
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.