AI agent recommends malware package to engineer; code review policy prevents installation

According to The Register, an engineer at Softjourn received a recommendation from an AI agent to install a malicious package formatted to resemble a legitimate library. The engineer's company policy of verifying AI recommendations on GitHub prevented the installation. Separately, CSO Online reported that security researchers at Wiz identified three backdoored Rust packages—arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9—published to crates.io on August 20, each introducing a typosquatted dependency that executed malicious code during compilation.

Topics

AI securityAgentic AISecurity

Sources

Go deeper

This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.