Several big businesses have published source code that incorporates a software package previously hallucinated by generative AI.

Not only that but someone, having spotted this reoccurring hallucination, had turned that made-up dependency into a real one, which was subsequently downloaded and installed thousands of times by developers as a result of the AI’s bad advice, we’ve learned. If the package was laced with actual malware, rather than being a benign test, the results could have been disastrous.

  • lurch (he/him)
    link
    fedilink
    English
    arrow-up
    1
    ·
    8 months ago

    when it gets someone shell access it barely matters if it’s prod or a dev system or whatever. it’s a solid foothold for an attacker to creep onto prod eventually.