New research reveals how attackers can hijack leading AI-powered coding tools using nothing but innocent-looking GitHub comments and PR titles.