zlacker

[parent] [thread] 1 comments
1. skrebb+(OP)[view] [source] 2026-01-30 19:12:07
You can tell immediately which commenters here didn't read past the clickbait headline.
replies(1): >>Legend+N
2. Legend+N[view] [source] 2026-01-30 19:16:15
>>skrebb+(OP)
Agreed. This is a standard supply chain attack that has little to do with AI except that it is written in the 'english-as-a-scripting-language' that LLMs execute.

Every repository is vulnerable to this kind of attack, and pip/npm have been attacked in many times in similar ways.

[go to top]