Several interesting attacks in this one. What's curious is that each malicious PR discussed used a different attack.
A lot of them are injection attacks. But my favorite of all of them: rewrote CLAUDE.md so the reviewing agent took on different directives. That attack kinda rules ngl