AI Threats

The GitHub Account That Was Too Perfect: How Attackers Are Weaponizing Open Source Trust

A pull request on GitHub exposed a new kind of attack: instead of injecting malicious code, attackers are fabricating entire identities to bypass human review. With fake accounts, manufactured credibility, and possibly AI-driven participants, the trust that powers open source has become the attack surface itself.