BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

A Departed Employee’s Token Quietly Opened 170 Private Security Repositories

The employee had left. The token had not. GitHub traced the access path back to the wider TanStack supply-chain incident.

Read the article

Current reporting

Latest intelligence

View all articles ↗

How Plugin4Shell Made Reviewed AI Coding Plugins Run Different Code

A commit hash is supposed to answer a simple question: exactly which code will run? Plugin4Shell shows that four popular AI coding agents recorded the right-looking pin but failed to verify that Git had actually placed that commit in the working directory.

AIR Security's research covers Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. A malicious plugin repository owner could create a branch whose name resembled the pinned commit. On Git hosts that permit the ambiguous reference, checkout could resolve to the branch instead. The agent then loaded the resulting plugin without checking that the working tree matched the reviewed commit object.

A marketplace could correctly store a reviewed hash and still lose control at installation time. The vulnerable agent delegated reference resolution to Git and treated a successful checkout as proof that the pin had been honoured. Background plugin updates made the path zero-click in products where automatic updates were enabled.

Git-host behaviour changes exposure. GitHub rejects some branch names that look like full commit hashes, limiting the demonstrated technique there. Bitbucket and self-hosted Git services may allow the conflicting name. That is why a safe conclusion cannot be based only on which marketplace a company uses.

No malicious exploitation has been established. AIR produced a working proof of concept against the four agents during coordinated research. The absence of an observed campaign does not remove the supply-chain consequence, but it must not be presented as an active breach.

The wider lesson is that a pin is…

22 Sep 2026 · 3 min read

The Fake GitHub Download Arrived With a Microsoft-Signed EDR Killer

The download page looked like GitHub. The driver carried Microsoft's attestation. Neither fact made the software safe. Rapuncel combines search-optimised repositories impersonating more than 40 brands with a kernel driver designed to…

21 Sep 2026 · 3 min read

CISA Gave Three Linux Kernel Bugs a Three-Day Deadline

Three Linux kernel vulnerabilities entered CISA's Known Exploited Vulnerabilities catalogue on 18 September with a remediation date of 21 September. The three-day deadline is unusually short. It is also easy to misread:…

21 Sep 2026 · 3 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.