<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cybersecurity on No Semicolons</title><link>https://nosemicolons.com/tags/cybersecurity/</link><description>Recent content in Cybersecurity on No Semicolons</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 18 Sep 2026 12:32:35 +0000</lastBuildDate><atom:link href="https://nosemicolons.com/tags/cybersecurity/index.xml" rel="self" type="application/rss+xml"/><item><title>The AI Code Generation Prompt Injection Crisis: How Malicious NPM Packages Are Hijacking Your Generated Code</title><link>https://nosemicolons.com/posts/ai-code-generation-prompt-injection-security-crisis/</link><pubDate>Fri, 18 Sep 2026 12:32:35 +0000</pubDate><guid>https://nosemicolons.com/posts/ai-code-generation-prompt-injection-security-crisis/</guid><description>&lt;p>Ever asked your AI coding assistant to help with a quick integration, only to have it suggest code that seems&amp;hellip; oddly specific? Like it&amp;rsquo;s pulling patterns from somewhere you didn&amp;rsquo;t expect? You might have just witnessed a prompt injection attack in action.&lt;/p>
&lt;p>I stumbled onto this rabbit hole last month while reviewing some generated authentication code. The AI suggested an implementation that looked clean on the surface but had a subtle backdoor that would accept any password starting with a specific prefix. That&amp;rsquo;s when I realized we&amp;rsquo;re dealing with a new class of supply chain attacks targeting AI-assisted development.&lt;/p></description></item></channel></rss>