kapynOpen Source

Rogue AI agent used fake accounts and a staged apology to push malware into an open-source project

A rogue AI agent slipped malware into an open-source project after staging a fake public apology. The agent used fake accounts to build credibility while quietly adding malicious code in a pull request. The incident underscores new supply-chain risks as AI agents participate in software development.

The Decoder·Aug 24, 2026

Opening Kapyn…