Looks like the dev told an LLM to generate test files for a Shai Hulud detection app.

The LLM complied and generated malicious test files...

https://github.com/Cobenian/shai-hulud-detect/blob/main/test-cases/destructive-patterns/windows_payload.ps1

@struppigel this is like level 3 deep in the rabbit hole. I sometimes think about people observing this whole cyber-thing from the outside and about how confusing it must be :-)