AI agent recommends malware package to engineer; code review policy prevents installation
According to The Register, an engineer at Softjourn received a recommendation from an AI agent to install a malicious package formatted to resemble a legitimate library. The engineer's company policy of verifying AI recommendations on GitHub prevented the installation. Separately, CSO Online reported that security researchers at Wiz identified three backdoored Rust packages—arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9—published to crates.io on August 20, each introducing a typosquatted dependency that executed malicious code during compilation.
Topics
Sources
- Press Read article
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.