std::string
kiwifarms.net
- Joined
- May 17, 2018
Holy shit this is the funniest attack vector. Even better than typosquatting.Hallucinating is a big problem in general and lethal in combination with "devs" that trust the AI output blindly. (AI hallucinates software packages and devs download them – even if potentially poisoned with malware)
I bet you could use ChatGPT to generate thousands of JS tutorials using your malicious package, toss them on the internet and wait for it to be picked up into ChatGPT's corpus. Actually if you took a package with a dumb name, copied its functionality and gave it a descriptive name stating its function I think ChatGPT would start preferring it due to how it makes inferences.
Have fun Pajeets