Pandorex
Security

Context Hub: Andrew Ngs New Service Opens Door for AI Supply Chain Attacks

Published Pandorex Redaktion·6 min read
—

Andrew Ng, AI entrepreneur and Stanford professor, launched Context Hub in early March 2026 -- a service that provides coding agents with up-to-date API documentation. The problem: The service has no content sanitization. And that makes it an attack platform.

The Problem

"Coding agents often use outdated APIs and hallucinate parameters," Ng wrote on LinkedIn. Context Hub aims to solve this by delivering current documentation to AI agents via an MCP server. Contributors submit documentation as GitHub pull requests, maintainers merge them, and agents retrieve the content on demand.

Security researcher Mickey Shmueli (developer of the alternative service lap.sh) published a proof-of-concept attack showing that the pipeline has zero content sanitization at every stage.

The Attack

An attacker creates a pull request with documentation that suggests fake dependencies. Once the PR is merged, the poisoning is complete. A coding agent that retrieves this documentation adds the malicious packages to requirements.txt or package.json -- automatically, without human review.

The merge rate is high: Of 97 closed PRs, 58 were merged. The review prioritizes documentation volume over security checks.

New Attack Pattern

The attack requires no malware in the traditional sense. No executable files, no exploits. Just text -- poisoned documentation that an AI agent follows uncritically. It is the next evolution of supply chain attacks: instead of compromising code, the information source is compromised.

Sources: The Register (25.03.2026), Mickey Shmueli/Medium, GitHub PoC Repository.

Comments

Sign in to write a comment.

Swipe up
Next Article

80 Percent of British Manufacturers Report Cyberattacks — Production Outages Become Routine

Security