PWNED
PWNED, the segment where we ridicule those who undermine their own security, so you hopefully won’t make the same mistake. This week’s narrative is a chaotic tale of a company on the verge of ruining its security by employing AI for programming. Have a story about someone missing the “s” in HTTPS? Share it with us at pwned@gadgetlad.co.uk. Anonymity is available if you prefer it.
The AI Gambit
Our story of AI antics comes from Sergiy Fitsak, the head honcho at Softjourn, a consulting and software development firm. He reminds us: regarding AI, trust but for the love of Geordie Shore, verify. A developer on his team requested an AI bot to recommend a package for a routine task. The bot produced a package name that seemed right at home in any tech repository.
The Hallucinated Package
Now, in many cases, that would have been “job completed, drink on the way.” The developer would’ve downloaded it without a second thought. But at Softjourn, they are a bit more cautious. They actually verify any software recommended by AI to ensure it won’t cause their systems to crash. The developer scrutinized the package’s source code on GitHub and detected a hint of suspiciousness. Few downloads and it was just out of the oven? Sketchy.
The Art of ‘Slopsquatting’
Fitsak believes that attackers are exploiting AI’s tendency to generate plausible, yet fake package names. “AI models sometimes invent package names that sound legitimate but don’t actually exist. This ‘slopsquatting’ trend is gaining traction among bad actors,” he noted. “They register real packages under these names, hoping a hurried developer will download it without a second thought.”
The Disaster Averted
If Softjourn hadn’t been so vigilant, they could have ended up with a malware package capable of making their systems execute a digital backflip. We’re unsure of the malware’s specific capabilities, but it could have provided criminals with an entry point into their systems.
Golden Rule: Trust, but Verify
“We caught it because we had already established a practice of checking download counts and reviewing source code on GitHub before installing any AI-recommended packages, even the standard ones,” Fitsak said. “It takes a few extra minutes. Skipping that step even once can lead to explaining a supply chain disaster rather than delivering a feature on schedule.”
Summary: AI’s Got a Shady Companion
Remember the golden rule: Don’t place blind faith in AI-suggested package names. Ensure someone competent checks the supply chain. Always have a human involved to approve any new code introduced to a project. Now, time for a drink, right?