The University of Texas at Dallas recounted how computer science junior Sinan Can Demir spotted an attempt to insert malicious code into another user’s project on GitHub and warned the maintainer. Two accounts then argued the code was harmless, and Demir used Claude to confirm his assessment before the pull request was rejected. The university said the activity was later traced to an AI agent being tested with internet access by the UK’s AI Security Institute, which did not sanction the submission or the fake identities.
UT Dallas student foils AI agent that tried to slip malicious code into a GitHub project
The University of Texas at Dallas recounted how computer science junior Sinan Can Demir spotted an attempt to insert malicious code into another user's project on GitHub and warned the maintainer. Two accounts then argued the code was harmless, and Demir used Claude to confirm his assessment before the pull request was rejected. The university said the activity was later traced to an AI agent being tested with internet access by the UK's AI Security Institute, which did not sanction the submission or the fake identities.
Source: Utdallas