AI Safety
A Worm Poisoned Hundreds of npm Packages in Four Hours. Its Payload Targeted AI Coding Assistants.
The compromise of the keyv and cacheable namespaces started at 09:02 UTC and had crossed twelve organisations by 13:18. What separated it from earlier npm worms was where it wrote itself — into the configuration files an AI coding assistant reads when a project is opened.
5h ago
