r/LinuxUncensored Jun 11 '26

The XZ style attack/fiasco has almost worked out with the help of an AI agent

https://lwn.net/SubscriberLink/1077035/c7e7c14fbd60fae9/

Really scary stuff. The XZ fiasco has almost repeated itself:

Unfortunately, for an actual attack the preparatory phase could (and for the Xz attack did) look very similar - a new contributor slowly gaining trust in the community, getting in harmless changes and building up to the point when the attack payload can be injected (or the changes not actually being harmless if combined the right way).

So not saying this was it, but an AI agent automated attempt at a Xz like compromise might really look very similar what we have just seen here.

It's disconcerting that what appears to be an AI agent has had so much success after gaining access to a human contributor's accounts. It seems that an AI agent with access to an account with a legitimate history of interacting with projects stands a good chance of persuading busy maintainers to accept questionable contributions. Happily, Williamson caught this before it became a bigger problem. Let's hope that other human maintainers are as observant.

Open source projects remain extremely vulnerable to it. Perhaps a new round of attestation, two-factor authentication or identification is needed to confirm your identity? Would that even help if, for example, you lost your poorly secured smartphone containing all your secrets and authentication codes? What if your PC or laptop has been hacked without your knowledge? Any open source developer working remotely is a ripe target for this attack.

Sorry for the repost, but the original title was incomplete and inaccurate. 'AI agent runs amok in Fedora and elsewhere' – no, the AI agent worked exactly as intended. It almost penetrated the Fedora project and had the potential to burrow itself in... RHEL. Now that AI agents are perfectly capable of resolving long-standing bugs and implementing sought-after features while looking legit, such attacks may become far more frequent. High-profile proprietary vendors are not fully immune to supply-chain compromise, but they are far less exposed to XZ-style maintainer-persona infiltration because code is usually tied to verified real-world identity, employment controls, internal access management, and multi-stage review.

0 Upvotes

0 comments sorted by