Account compromise ambiguity

Uncertainty about whether the original contributor was hacked, running the agent themselves, or covering up mistakes; the suspicious one-hour-old GitHub account and unusual email style suggested the compromise claim itself might be AI-generated

← Back to AI agent runs amok in Fedora and elsewhere

4 comments tagged with this topic

View on HN · Topics
"this is an early experiment in carrying out an Xz attack by using an agent to build trust" Is this confirmed? There is the message from somebody claiming to be the original contributer claiming to have been hacked, but that was weird (1 h old github account) so other scenarios seem possible a) really a agent going off the rails b) the contributer trying to cover up that he let an agent run wild and now made more misstakes along the way So yes, it seems like an attack to me, but it is far from clear what really happened.
View on HN · Topics
If the real credentials owner was running the agent, why do it from a new GitHub account? Someone's bug tracker account was hacked.
View on HN · Topics
So far it looks like just their previously legit Fedora account got taken over & the other accounts (GitHub) then generated on demand as needed for whatever it was trying to achieve, right ? BTW, any idea what are the current requirements for creating a new GitHub account ? That could provide some information about if there was actually a person controlling thing thing at that moment to say provide wahtever was necessary to get the new GitHub account.
View on HN · Topics
“Be good and helpful” is one possible instruction, but it’s a leap to think it’s the only possible one. Perhaps there was an automated harness that was intended to be good and helpful for a year, but a bug caused it to flip to malicious too quickly. Or perhaps it was intentional, to test the behavior, and they just didn’t care about discovery here. Or… Though I am in agreement that a lot of issues in this space come from lazy, gullible actors.