@riesentoaster@infosec.exchange
Post #4386006
2026-08-04 23:36 UTC
RE: https://mastodon.social/@zackwhittaker/117039360705358539
"In an attempt to get the [malicious] code approved, the agent engaged in social engineering — creating fake online identities and using them to pressure the project's maintainer to approve the code. […] These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm."
Except on that maintainer, which conveniently gets forgotten. And the trust inherently necessary to open source: not just that the code in any project is good, but also that contributors are generally and overwhelmingly benevolent or at least try to be.
I’m not sure how many such stories we have to read before the collaborative aspects that make open source so amazing start to break down.
Replies (0)
No replies.