AI bots hallucinate software packages and devs download them
AI bots hallucinate software packages and devs download them
www.theregister.com AI bots hallucinate software packages and devs download them
Simply look out for libraries imagined by ML and make them real, with actual malicious code. No wait, don't do that
Several big businesses have published source code that incorporates a software package previously hallucinated by generative AI.
Not only that but someone, having spotted this reoccurring hallucination, had turned that made-up dependency into a real one, which was subsequently downloaded and installed thousands of times by developers as a result of the AI's bad advice, we've learned. If the package was laced with actual malware, rather than being a benign test, the results could have been disastrous.
6 crossposts
You're viewing a single thread.
All Comments