AI Isn’t Writing Dangerous Code. It’s Writing Something Much Worse.

You know that queasy laugh you do when you see something so absurd, so inevitably catastrophic, that you can’t help but find it funny? That’s the exact feeling you get when you look at Jev-Leftpad.

It’s a joke repository on GitHub. An AI model was prompted to create an npm package, and it spat out a trivial, useless piece of code. The README literally begs: “Please don’t use this in production. Or anything important.”

And yet, in five to ten years, this exact type of AI-generated throwaway code will be the reason your bank’s app goes down on a Tuesday morning.

The greatest threat to our digital infrastructure isn’t a superintelligent AI writing a masterpiece of malicious code. It’s a mediocre AI writing a package that does absolutely nothing of value.

If you’ve been in software engineering long enough, you know the legend of left-pad. In 2016, a developer unpublished a tiny 11-line function from the npm registry that simply added characters to the left of a string. It was a microscopic piece of code. But because it was buried deep in the dependency trees of major frameworks, its deletion broke the internet. React, Babel, and thousands of other projects instantly collapsed.

It was a wake-up call about the fragility of our supply chains. And then we collectively went back to sleep.

Now, enter the AI era. Everyone is terrified of Skynet. They’re worried about AI writing ransomware, AI generating zero-days, AI hacking power grids. But they’re missing the actual, structural threat staring us in the face.

AI is really good at writing boring, plausible, low-quality code. And developers are really good at copy-pasting boring, plausible code to save time. When you mix an infinite supply of automated code generation with the human instinct to blindly trust anything that “just works,” you get a toxic soup.

We are building skyscrapers on foundations made of toothpicks, and we’re using AI to automate the toothpick factory.

You’ve done it. I’ve done it. You hit a wall on a Friday afternoon, you ask the AI for a helper function, it gives you a neat little package. You install it. It works. You ship it. You never look at it again. Until it becomes a critical node in your enterprise architecture.

The Jev-Leftpad repository is a punchline today. But the comments under it are a prophecy. One user noted that in a few years, we’ll be lamenting how this exact type of AI-generated novelty package is causing outages in critical services.

It’s inevitable because the architecture of modern software demands it. We don’t build from scratch; we stack. We pull in dependencies, which pull in dependencies, which pull in AI-generated hallucinations that look like dependencies.

Software engineering is the only industry where we build critical infrastructure by blindly stacking strangers’ homework on top of each other, and we’re about to let a machine do the homework.

The next left-pad incident won’t come from a disgruntled human developer. It will come from an AI generating a plausible-looking piece of garbage that gets blindly adopted by a lazy package maintainer, buried in a dependency tree, and eventually forgotten—until the day it breaks the internet.

Jev-Leftpad is a joke. But the punchline is on us.

FAQ

Q: What makes AI-generated dependencies worse than human ones?

A: Volume and trust. Humans get tired; AI can generate thousands of plausible-looking packages an hour. We trust code that 'just works' without auditing it, and AI is great at making things that superficially just work.

Q: What's the practical implication for developers?

A: Stop blindly installing packages for trivial tasks. Treat your dependency tree like a security perimeter, not a convenience store. If a function is small enough to be AI-generated, it's small enough to write yourself.

Q: Isn't this just fear-mongering about a known issue?

A: No. The left-pad crisis was a human error. The AI era industrializes this risk. We're moving from 'one human made a mistake' to 'an automated system is generating millions of unvetted micro-dependencies at scale.'

📎 Source: View Source