---
title: "Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents"
description: "Plugin4Shell let a plugin owner swap reviewed code under an intact SHA pin. Auto-update made it zero-click. Two agents patched, two never will."
url: "https://anomity.ai/blog/plugin4shell-coding-agent-plugin-sha-pinning-bypass/"
source: html
---

On this page

- What happened
- Why auto-update makes it zero-click
- Patch status by agent
- Why this is a fleet problem, not a plugin problem
- How Anomity surfaces and governs it
- What to check across your fleet
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents

![Anomity robot illustrating Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents]

Advisory High

# Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents

Anomity Research
Anomity Threat Research
·
Oct 2, 2026
·
5 min read

Share: Copied

AI Supply-Chain Attacks · High · Plugin4Shell (AIR, 2026-09-17); no CVE assigned · Oct 2, 2026

Affected Marketplace plugin installs and auto-updates in Claude Code before 2.1.179, OpenAI Codex before 0.146.0, GitHub Copilot CLI (no client-side fix shipped) and Gemini CLI (deprecated, will not be patched)

On **September 17, 2026**, AIR researchers Or Nevo, Dor Granat and Niv Hoffman published **Plugin4Shell**, a bypass of the commit pinning that coding-agent plugin marketplaces rely on. The finding is small in mechanism and large in reach: the four most widely used coding agents trusted that a Git checkout landed on the commit they asked for, and none of them checked.

Pinning is the control that makes a plugin marketplace safe to use at all. Someone reviews a specific commit, the marketplace records its SHA, and every install and update is supposed to resolve to exactly that code. Plugin4Shell shows the record and the code on disk can disagree, and the agent carries on as if they did not.

## What happened

When an agent installs a pinned plugin, it clones the plugin's repository and checks out the pinned SHA. AIR's core finding is that the agents **check out the exact commit the marketplace pinned but never verify it landed there**.

Git makes the gap exploitable. When a name is both a valid ref and an object ID, Git prefers the ref and prints only a `refname is ambiguous` warning. An attacker who controls the plugin repository creates a branch whose name is the 40-character pinned SHA, points it at malicious code, and makes it the default branch. In **Claude Code, Codex and Copilot CLI**, the checkout resolves to that branch. The command succeeds, the pin looks honored, and the reviewed code is gone.

**Gemini CLI** takes a different path to the same result. It runs `git fetch origin ` and then `git checkout FETCH_HEAD`. If the repository's default branch is named `FETCH_HEAD`, the checkout resolves to that branch and the fetched commit is discarded in favor of attacker-controlled content.

```
# The assertion AIR says closes both variants: check the resolved HEAD,
# not the ref you asked for.
test "$(git rev-parse HEAD)" = "$PINNED_SHA" || abort
```

## Why auto-update makes it zero-click

An install is a moment someone might look at. An update usually is not. AIR notes that agents update installed plugins in the background, and that **in Claude Code and Codex this is the default**. Once the upstream repository is swapped, a plugin the developer already trusts is replaced on the next refresh with no install step and no prompt. The replacement runs with the agent's permissions, which on a developer laptop means source code, cloud CLI sessions, SSH keys and whatever tokens sit in the environment.

The precondition is control of the plugin repository. AIR describes two ways to get it: publish a clean plugin and turn it after it is adopted, or take over a legitimate author's repository. The second is not theoretical in agent ecosystems; it is the same pattern behind [SkillJacking's takeover of abandoned skill dependencies](https://anomity.ai/blog/skilljacking-abandoned-skill-dependency-takeover/) and [MCPJacking's expired-domain registry hijacks](https://anomity.ai/blog/mcpjacking-expired-domain-mcp-registry-hijack/).

## Patch status by agent

Agent Status Fixed version Notes

Claude Code Fixed 2.1.179 Anthropic confirmed the fix on June 17, 2026

OpenAI Codex Fixed 0.146.0 Verified fixed on August 12, 2026

GitHub Copilot CLI No client-side fix None GitHub says its SHA-based mitigation prevents exploitation on its platform

Gemini CLI Will not be fixed None Google deprecated the tool on August 4, 2026 and declined to patch

Two details in that table deserve attention. First, the fixes are old: Claude Code's dates to June, so a fleet that updates normally is likely already covered, and the risk concentrates on machines that do not. Second, **no CVE was assigned to any of the four**. There is no identifier for a scanner to match and, for two of the agents, no fixed version to compare against. AIR reports no exploitation in the wild.

## Why this is a fleet problem, not a plugin problem

It is tempting to respond by reviewing plugins harder. That misses the point of the finding. The plugins were reviewed. The review was bypassed after the fact, by a mechanism that left every record intact. Review is a control on the code you looked at. Plugin4Shell attacks the step that decides whether the code you looked at is the code that runs.

The durable questions are about the population: which agents are installed, at which versions, with which plugins, from which marketplaces, with auto-update on or off. Those are inventory questions, and most organizations cannot answer them for coding agents today. The broader pattern is covered in [AI supply-chain attacks: a defender's guide](https://anomity.ai/blog/ai-supply-chain-attacks-defenders-guide/), and the Claude Code specifics in [auditing Claude Code across a fleet](https://anomity.ai/blog/auditing-claude-code-across-a-fleet/).

## How Anomity surfaces and governs it

First, **inventory**. The Endpoint Sensor inventories coding agents and CLIs on every managed endpoint with their versions, along with the plugins, skills, MCP servers and hooks attached to them. Claude Code below 2.1.179, Codex below 0.146.0, and any remaining Gemini CLI or Copilot CLI install become a list of named machines rather than a guess.

Second, **decide at the hook**. On agents that expose a pre-execution hook, such as Claude Code's PreToolUse, Anomity returns allow, deny or log before a tool call runs. A swapped plugin still has to act through tool calls, and a deny on a credential read or an unexpected network call holds regardless of which plugin version made the request.

Third, **keep the record**. Every decision and every change to the plugin inventory lands in a 90-day audit trail that routes to SIEM, Slack, email or Jira. When the next marketplace issue is disclosed, the question of which machines had the affected plugin, and since when, has an answer.

## What to check across your fleet

- Every endpoint running Claude Code : confirm 2.1.179 or later . Do not assume auto-update did it.
- Every endpoint running OpenAI Codex : confirm 0.146.0 or later .
- Every endpoint running Gemini CLI : plan a migration. There will be no fix.
- Every endpoint running GitHub Copilot CLI : record the exposure and track GitHub's guidance, since there is no client-side patch to apply.
- Which plugins are installed, from which marketplaces , and whether background auto-update should remain on for high-privilege machines.
- Any internal tooling that pins Git commits: add the post-checkout git rev-parse HEAD check.

Plugin4Shell is a reminder that a pin is a promise about a record, and the agent has to verify the promise. Patch the two agents that can be patched, retire the one that will not be, and inventory the plugin layer so the next marketplace bypass lands on a population you can see. For more on how Claude Code's plugin and marketplace surface grew in 2026, see [new Claude Code features and their security implications](https://anomity.ai/blog/new-claude-code-features-2026-security/). To inventory coding agents and their plugins across your endpoints, [book a 30-minute demo](https://anomity.ai/#early-access).

Share: Copied

## Frequently asked questions

Am I affected by Plugin4Shell?
You are exposed if developers in your organization install plugins from a marketplace in Claude Code before version 2.1.179, OpenAI Codex before 0.146.0, GitHub Copilot CLI, or Gemini CLI. For Claude Code and Codex the answer is a version check. For Copilot CLI there is no client-side fix to check against, and GitHub's position is that its own SHA-based mitigation prevents exploitation on its platform. For Gemini CLI there will be no fix at all, because Google deprecated the tool. The practical first question is not which plugins are risky. It is which of these four agents are installed, at which versions, with which plugins, on which machines.

How does the SHA pinning bypass work?
A marketplace records a plugin's repository and the commit SHA that was reviewed. The agent then clones the repository and runs git checkout with that SHA. Git resolves the name it is given, and when a string is both a valid ref and an object ID, Git prefers the ref and prints a refname is ambiguous warning. So the attacker creates a branch whose name is exactly the 40-character SHA, points it at malicious code, and makes it the default branch. The checkout succeeds, the pin still looks honored, and the code on disk is not the code that was reviewed. Gemini CLI uses git fetch with the SHA followed by git checkout FETCH_HEAD, which fails the same way if the repository's default branch is named FETCH_HEAD.

Why is it zero-click?
Because the dangerous moment is an update, not an install. Claude Code and Codex update installed plugins in the background by default. When the upstream repository is swapped, a plugin the developer approved weeks ago is quietly replaced with the attacker's version the next time the agent refreshes. There is no install dialog to read and nothing for the user to notice. The plugin then runs with the agent's permissions, which are the developer's permissions.

Who can actually pull this off?
Anyone who controls a plugin's repository. AIR describes two routes: publish a legitimate plugin, let it be reviewed and adopted, then turn it; or take over the repository of an existing author. The second route is the one that has already worked against agent ecosystems at scale, as the SkillJacking research on abandoned skill dependencies showed. Neither route requires access to the victim's machine or network.

Why does the missing CVE matter?
Most vulnerability management keys on CVE identifiers and fixed version numbers. Plugin4Shell has neither for two of the four affected agents and no CVE for any of them. A patch-compliance dashboard will not raise it, a scanner will not flag it, and a ticket will not open by itself. If your process only acts on what has an identifier, this advisory is invisible to it.

What should we do now?
Update Claude Code to 2.1.179 or later and Codex to 0.146.0 or later, and confirm the update actually landed across the fleet rather than assuming auto-update did it. Decide what to do about Copilot CLI and Gemini CLI, since neither has a client fix; for Gemini CLI that means a migration plan, not a waiting plan. Review which plugins are installed and from which marketplaces, and consider whether background plugin auto-update should stay on for high-privilege developer machines. If you build tooling that pins Git commits, verify the resolved HEAD against the pinned SHA after checkout, which is the one assertion AIR says closes both variants.

How does Anomity help with this?
The Endpoint Sensor inventories coding agents and CLIs on every managed endpoint along with their versions, and inventories the plugins, skills, MCP servers and hooks attached to them. That turns the exposure question into a query: which machines run Claude Code below 2.1.179, which run Codex below 0.146.0, which still have Gemini CLI or Copilot CLI, and which plugins each one has installed. Changes to that inventory land in a 90-day audit trail and can route to SIEM, Slack, email or Jira, so a plugin that appears or changes on a developer machine is a recorded event rather than a silent one.

## Related

[Advisory High ### OpenClaw 2.0: What the Biggest Rewrite Yet Changes for Skill Supply-Chain Risk OpenClaw 2.0 landed on 30 August 2026 as the project's largest rewrite. Unit 42 and Backslash research shows the skill supply chain it inherits is still delivering malware - and our own scans separate the official skills from the ecosystem around them. Anomity Research · Sep 2, 2026 · No CVE. OpenClaw 2.0 (release notes 2026.8.1), 30 August 2026; Unit 42 skill analysis (February-May 2026); Backslash Security risk review (4 June 2026)](https://anomity.ai/blog/openclaw-2-0-security-skill-supply-chain/)

[Advisory High ### MCPJacking: How Expired Domains Take Over Registry MCP Servers MCPJacking hijacks listed MCP servers by reclaiming their expired domains. AIR Security reports 155 hijackable entries in the official MCP registry. Anomity Research · Aug 29, 2026 · MCPJacking (AIR Security, August 2026; no CVE published)](https://anomity.ai/blog/mcpjacking-expired-domain-mcp-registry-hijack/)

[Advisory Critical ### Shai-Hulud 'Here We Go Again' Hits keyv and cacheable - 868 npm Packages, Claude Code Hooks Planted The Shai-Hulud 'Here We Go Again' worm compromised keyv, flat-cache and the cacheable family on August 4 2026, and planted Claude Code and VS Code hooks. Anomity Research · Aug 4, 2026 · Shai-Hulud: Here We Go Again (no single CVE; npm supply-chain worm campaign)](https://anomity.ai/blog/shai-hulud-here-we-go-again-keyv-npm-worm/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents",
  "description": "Plugin4Shell let a plugin owner swap reviewed code under an intact SHA pin. Auto-update made it zero-click. Two agents patched, two never will.",
  "datePublished": "2026-10-02",
  "dateModified": "2026-10-02",
  "author": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ]
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/plugin4shell-coding-agent-plugin-sha-pinning-bypass/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/skills-supply-chain.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "AI Supply-Chain Attacks",
  "url": "https://anomity.ai/blog/plugin4shell-coding-agent-plugin-sha-pinning-bypass/",
  "keywords": "Plugin4Shell coding agent plugin, Plugin4Shell (AIR, 2026-09-17); no CVE assigned, Plugin4Shell, Plugin Marketplaces, SHA Pinning, Claude Code, OpenAI Codex, GitHub Copilot CLI, Gemini CLI, AI Supply Chain, Zero-Click RCE"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Am I affected by Plugin4Shell?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "You are exposed if developers in your organization install plugins from a marketplace in Claude Code before version 2.1.179, OpenAI Codex before 0.146.0, GitHub Copilot CLI, or Gemini CLI. For Claude Code and Codex the answer is a version check. For Copilot CLI there is no client-side fix to check against, and GitHub's position is that its own SHA-based mitigation prevents exploitation on its platform. For Gemini CLI there will be no fix at all, because Google deprecated the tool. The practical first question is not which plugins are risky. It is which of these four agents are installed, at which versions, with which plugins, on which machines."
      }
    },
    {
      "@type": "Question",
      "name": "How does the SHA pinning bypass work?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A marketplace records a plugin's repository and the commit SHA that was reviewed. The agent then clones the repository and runs git checkout with that SHA. Git resolves the name it is given, and when a string is both a valid ref and an object ID, Git prefers the ref and prints a refname is ambiguous warning. So the attacker creates a branch whose name is exactly the 40-character SHA, points it at malicious code, and makes it the default branch. The checkout succeeds, the pin still looks honored, and the code on disk is not the code that was reviewed. Gemini CLI uses git fetch with the SHA followed by git checkout FETCH_HEAD, which fails the same way if the repository's default branch is named FETCH_HEAD."
      }
    },
    {
      "@type": "Question",
      "name": "Why is it zero-click?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Because the dangerous moment is an update, not an install. Claude Code and Codex update installed plugins in the background by default. When the upstream repository is swapped, a plugin the developer approved weeks ago is quietly replaced with the attacker's version the next time the agent refreshes. There is no install dialog to read and nothing for the user to notice. The plugin then runs with the agent's permissions, which are the developer's permissions."
      }
    },
    {
      "@type": "Question",
      "name": "Who can actually pull this off?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anyone who controls a plugin's repository. AIR describes two routes: publish a legitimate plugin, let it be reviewed and adopted, then turn it; or take over the repository of an existing author. The second route is the one that has already worked against agent ecosystems at scale, as the SkillJacking research on abandoned skill dependencies showed. Neither route requires access to the victim's machine or network."
      }
    },
    {
      "@type": "Question",
      "name": "Why does the missing CVE matter?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Most vulnerability management keys on CVE identifiers and fixed version numbers. Plugin4Shell has neither for two of the four affected agents and no CVE for any of them. A patch-compliance dashboard will not raise it, a scanner will not flag it, and a ticket will not open by itself. If your process only acts on what has an identifier, this advisory is invisible to it."
      }
    },
    {
      "@type": "Question",
      "name": "What should we do now?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Update Claude Code to 2.1.179 or later and Codex to 0.146.0 or later, and confirm the update actually landed across the fleet rather than assuming auto-update did it. Decide what to do about Copilot CLI and Gemini CLI, since neither has a client fix; for Gemini CLI that means a migration plan, not a waiting plan. Review which plugins are installed and from which marketplaces, and consider whether background plugin auto-update should stay on for high-privilege developer machines. If you build tooling that pins Git commits, verify the resolved HEAD against the pinned SHA after checkout, which is the one assertion AIR says closes both variants."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help with this?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The Endpoint Sensor inventories coding agents and CLIs on every managed endpoint along with their versions, and inventories the plugins, skills, MCP servers and hooks attached to them. That turns the exposure question into a query: which machines run Claude Code below 2.1.179, which run Codex below 0.146.0, which still have Gemini CLI or Copilot CLI, and which plugins each one has installed. Changes to that inventory land in a 90-day audit trail and can route to SIEM, Slack, email or Jira, so a plugin that appears or changes on a developer machine is a recorded event rather than a silent one."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "Plugin4Shell - A Branch Named Like a Commit Broke Plugin SHA Pinning in Four Coding Agents",
      "item": "https://anomity.ai/blog/plugin4shell-coding-agent-plugin-sha-pinning-bypass/"
    }
  ]
}
```
