AI coding agents can be tricked into installing malware via ‘clean’ GitHub repositories