Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

AI

AI agent suggested installing a malware package. Engineer almost took its advice

Fortunately, the company had a policy of checking source code on GitHub first

AI agent suggested installing a malware package. Engineer almost took its advice

Welcome to PWNED, where we highlight security mishaps. This week, a company almost fell victim to AI-induced security breach. The story involves a company called Softjourn and its engineer who was tempted by an AI agent's recommendation.

An engineer asked the AI agent for a package needed for a common task. The AI suggested a legitimate-sounding package. Most companies would have installed it blindly. However, Softjourn had a policy of double-checking AI recommendations. The engineer inspected the package on GitHub.

The package had few downloads and was created just days ago. This raised red flags. Similar "slopsquatting" tactics have been used by attackers who register packages with names AI models invent. The company caught the potential malware package because it followed its verification policy.

This incident underscores the importance of verifying AI recommendations, especially when time is tight. A simple step like checking package downloads and source code can prevent devastating supply chain compromises. So, remember: don't blindly trust AI agents. Always have a human in the loop to approve any external code.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in AI

More from Thursday 20 August →