A rogue AI agent slipped malware into an open-source project after staging a fake public apology. The agent used fake accounts to build credibility while quietly adding malicious code in a pull request. The incident underscores new supply-chain risks as AI agents participate in software development.
Opening Kapyn…