Google Antigravity is legitimate software, but that does not make every download or every use safe. Google’s official acquisition path is antigravity.google. Separately, Pillar Security reported a vulnerability involving prompt injection and sandbox escape, while Malwarebytes documented a fake-download campaign that delivered credential-stealing malware. Those are different threats, with different warning signs and responses.
What Google Antigravity is—and where to get it
Antigravity is an agentic software-development ecosystem, not a physical product. Google introduced it on November 18, 2025, and later described a broader set of capabilities: a standalone desktop app, command-line interface, API access, IDE integrations, subagents, and asynchronous or scheduled work. On May 19, 2026, Google announced Antigravity 2.0 as a separate desktop app for macOS, Linux, and Windows, with synchronous and asynchronous agents.
To obtain it, navigate directly to antigravity.google. Avoid search ads and lookalike addresses, especially hyphenated domains. Malwarebytes documented a campaign using google-antigravity[.]com, which is not the official address.
What the security reports found
Pillar Security: a prompt-injection path to code execution
On April 20, 2026, Pillar Security published a report describing a vulnerability in Antigravity. Its researchers said that crafted input passed to the find_by_name operation could inject flags into the native fd file-search utility. That could turn a search into arbitrary code execution and escape the product’s sandbox. The reported chain began with prompt injection and reached code execution because untrusted input was not safely handled before the utility ran.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Pillar Security said it submitted its initial proof of concept to Google through the AI Vulnerability Reward Program on January 7, 2026. The available report establishes the researchers’ finding and disclosure, but does not establish the vulnerability’s current patch status. Do not treat the report as proof that every current Antigravity installation remains vulnerable—or as proof that it has been fixed. Check Google’s current product security information before relying on a particular version.
Malwarebytes: a fake installer that stole credentials
On April 21, 2026, Malwarebytes reported a typosquatting campaign hosted at google-antigravity[.]com. The site offered a repackaged installer named Antigravity_v1.22.2.0.exe. It appeared functional, but also launched a PowerShell downloader and later-stage information-stealing code.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Malwarebytes identified theft targets including browser passwords and autofill data, session cookies, Discord and Telegram sessions, Steam logins, FTP credentials, and cryptocurrency-wallet files. This was a distribution and social-engineering attack: the victim was induced to run an unofficial installer, and the malware operated on the host system. That differs from the researcher-reported product vulnerability, which involved malicious input reaching a utility through an agent workflow.
How the two threats differ
| Question | Reported product vulnerability | Fake-download campaign |
|---|---|---|
| Attack path | Prompt injection and crafted input passed to find_by_name, according to Pillar Security. |
A lookalike site supplied a modified installer, according to Malwarebytes. |
| What a user might do | Open or work with content that supplies malicious instructions to an agent; the specific conditions depend on the attack scenario. | Download and run an installer from an unofficial site. |
| Boundary or system at risk | The report describes escape from Antigravity’s sandbox into code execution. | The installer ran malware on the computer, with credential and wallet data among the reported targets. |
| Primary response | Use a current, trusted product version and contain suspected agent-driven execution; do not assume sandboxing alone neutralizes hostile input. | Treat the host and credentials as potentially compromised; follow the incident-response steps below. |
How to download Antigravity more safely
- Type
antigravity.googleinto the browser yourself or use a bookmark you already trust. Do not follow a search ad or a link on an unfamiliar download page. - Check the address bar before downloading. A page at
google-antigravity[.]comis not the official Google address. - Download only through Google’s official site and use the installer obtained there. A plausible filename, working interface, or version number does not establish that an installer is authentic.
- For work-managed devices, follow your organization’s approved software distribution process and ask IT or security staff to verify the package if its origin is unclear.
What to do if you ran an unofficial installer
Malwarebytes advises treating an installation from anywhere other than antigravity.google as suspect. Its report listed the network indicators opus-dsn[.]com, captr.b-cdn[.]net, and 89[.]124[.]96[.]27. These indicators can support investigation, but their absence alone does not prove a computer is clean.
Recommended Free Tools
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Contain the device. Disconnect it from sensitive accounts and networks; avoid using it to sign in to email, financial services, or work systems. If it is managed by an employer, contact the IT or security team promptly and follow their instructions.
- Use a separate, clean device for account recovery. Sign out of active sessions, then change passwords for email and financial accounts. Prioritize accounts that can reset other passwords.
- Revoke exposed credentials. Rotate API keys, SSH keys, cloud credentials, and other secrets that were stored on or used from the affected computer. Notify the owners of affected work or cloud systems.
- Protect cryptocurrency. If wallet files or credentials may have been exposed, move funds to a clean wallet using a clean device. Do not enter wallet recovery phrases on the suspected machine.
- Investigate and rebuild. Security staff can check the listed network indicators and examine the installer and host. Malware scanning may help with triage, but a clean scan is not proof that a potentially compromised machine is safe. Malwarebytes recommends wiping and reinstalling Windows.
Why attackers target AI coding tools
Agentic development tools can interact with code, files, and utilities, so a flaw in how an agent handles untrusted instructions may have consequences beyond an ordinary bad answer. Separately, developers’ computers and credentials can provide access to valuable code repositories, cloud systems, messaging accounts, and financial assets. The Pillar Security and Malwarebytes reports illustrate those two routes: exploiting a product behavior and persuading users to install malware.
The wider threat environment is moving quickly. On September 8, 2026, Google Threat Intelligence Group reported that adversaries were progressing from basic prompting toward agentic workflows and AI-enabled automation. In one Q2 2026 case, the group said a cloud compromise was followed by planning, building, and execution of a mass credential-harvesting campaign in under six hours. That is a report about adversary activity, not evidence that Antigravity itself was used in that campaign.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
On September 18, 2026, Google engineers said continuous agentic scanning across hundreds of millions of lines of code prevented hundreds of vulnerabilities per month from reaching production. That describes Google’s defensive scanning work; it does not establish Antigravity’s security status or negate the specific findings reported by Pillar Security and Malwarebytes.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →

