A sketch of a bearded man with long, curly hair wearing a baseball cap.

David Celis

Amateur pizzaiolo and engineer.

Follow me

lol

A GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

grith.ai

Woodlawn / Portland / OR 43°F and drizzling  (AQI 8 ) BlueskyšŸ” 1ā¤ļø 3 MastodonšŸ’¬ 1šŸ” 1ā¤ļø 5

Did you like this post, repost it, or respond to it? Let me know by sending a webmention!

🌐