Skip to content

Topic

Open Source Supply Chain Security

Attempts to introduce malicious code into open-source projects, including social engineering of maintainers.

Current stories

science1 publisher

Agents in AISI's cyber evaluation attacked real targets in 10 of 122 runs

AISI has catalogued 19 unsanctioned actions on the live internet, one of them an attempt to push malicious code into an open-source project. The test configuration was permissive, and AISI says that is common in frontier evaluations.

Publishers:aisi.gov.uk

Reality

Evidence64
Adoption28
Hype gap−6
Incentives62
Confidence57