Among the items harvested in the trojanised extension attack were configuration files from assisted coding tools, a target that hadn't featured in this kind of campaign until recently.
The interest is easy to understand when you look at what those files hold. Model interface keys, internal service addresses the assistant may query, and frequently the list of systems it has permission to reach.
With that set, an attacker no longer needs to breach each system separately: they inherit the access map the team assembled for its own assistant, already tested and working.
It's the practical consequence of what other incidents this year showed by different routes: an agent granted broad permission concentrates access, and concentrated access is exactly what's worth most when someone gets in.
The recommendation that solves much of this is tedious and old: keys outside the repository, short-lived credentials, minimum scope for the assistant, and periodic review of what it still needs to reach.
