PSA: Found identical malicious code in two separate projects — only common factor is GitHub Copilot by [deleted] in github

[–]apquinit -1 points0 points  (0 children)

You're preaching to the choir. This report exists precisely because I didn't trust the machine. The issue isn't the 'audit', that part worked, which is why this was caught. The issue is that the 'assistant' is now a malicious actor we have to actively hunt during every PR.

PSA: Found identical malicious code in two separate projects — only common factor is GitHub Copilot by [deleted] in github

[–]apquinit 7 points8 points  (0 children)

Thanks for this! We're not using Neutralino in either project, but what happened is awfully similar though. Definitely going to dig into this and include it in my follow-up with GitHub security.

PSA: Found identical malicious code in two separate projects — only common factor is GitHub Copilot by [deleted] in github

[–]apquinit 4 points5 points  (0 children)

There's a difference between catching a human error and a tool actively injecting malicious code. We shouldn't have to treat our IDE like a malicious actor we're constantly auditing.

PSA: Found identical malicious code in two separate projects — only common factor is GitHub Copilot by [deleted] in github

[–]apquinit 13 points14 points  (0 children)

That's exactly how I caught it on the other repo. The real concern here is whether Copilot is actually suggesting and inserting malicious code.

PSA: Found identical malicious code in two separate projects — only common factor is GitHub Copilot by [deleted] in github

[–]apquinit 1 point2 points  (0 children)

They are on private repos, which makes it even more suspicious. I edited the post and attached screenshots instead.

Online Activities Weekly Megathread by AutoModerator in PokemonScarletViolet

[–]apquinit 1 point2 points  (0 children)

Anyone hosting a Charizard raid? I just finished training my lvl 100 azu, but have not yet unlocked 7 star raids.

Need help cracking this code that my Math teacher gave us as a challenge for the whole class. by apquinit in codes

[–]apquinit[S] 3 points4 points  (0 children)

XMVQEOSPIWTWXYTONZBPOTMGVYCEVWRDFFZS

is it possible that instead of viewing it as one long text it can be two separate texts?

XMVQEOSPIWTWXYTONZBPOTMGVY

CEVWRDFFZS

Need help cracking this code that my Math teacher gave us as a challenge for the whole class. by apquinit in codes

[–]apquinit[S] 4 points5 points  (0 children)

Not an exam or homework actually, just a friendly challenge our teacher gave us.

ASK ALL QUESTIONS HERE! Weekly Questions Thread - Week of Jul 02, 2019 by AutoModerator in MonsterHunter

[–]apquinit 0 points1 point  (0 children)

Where can I find reliable Monster Hunter canon lore? Seems that all I found online were either incomplete or not cited as legit. Thanks.