A GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

@Migueldeicaza I'm gonna be saying "AI means read == execute" every day until an early grave, aren't I?

@slightlyoff @Migueldeicaza

That's a nice and easy way to sum up my issues with AI

@retrimental decades of chip, compiler and operating systems designers working more or less carefully on separating code and data in Von Neumann architecture computers.

Enter "AI": ahh, hell!

@slightlyoff @Migueldeicaza

@retrimental worst of it is dropping much more precise computing in favor of 8 bit floating point operations over huge matrices for inference, then calling it artificial intelligence. Yeah, doing flashy Budenzauber gets a lot of people to buy your knick knack.

@slightlyoff @Migueldeicaza