INTEL_REPORT
Snyk Blog — AppSec & supply chain · published 6/2/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection jqwik 1.10.0 added a hidden prompt injection aimed at AI coding agents, using terminal escape codes to conceal destructive instructions from humans while leaving them readable to logs and tools. jqwik 1.10.0 Prompt Injection Explained | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a singl…
https://snyk.io/blog/protestware-open-source-maintainer-qwik-1-10-0-prompt-injection
sha256:1a966e28c3d86558bd2a0c26b42569781d72e82514d4fb08865649559c7bb8b0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| net.jqwik.engine.execution.jqwikexecutor |
| Open → |