Back
A satirical incident report: how seven AI security gates missed a malicious package
SiTech AI Team3 წთ. საკითხავი

A satirical incident report: how seven AI security gates missed a malicious package

Andrew Nesbitt's fictional CVE-2026-LGTM report follows a malicious package through seven AI security gates, a prompt-injected triage bot and a 2,200-word treaty signed by two instances of the same model.

On 26 June 2026 the software supply chain researcher Andrew Nesbitt published "Incident Report: CVE-2026-LGTM" on his blog — a fictional incident report, subtitled "A series of unfortunate agents", written in the format of a real breach postmortem. The identifier does not exist in any CVE database: the post is satire, a follow-up to his earlier invented report on "CVE-2024-YIKES", and its target is the growing habit of putting language models in charge of security review.

Seven gates, seven different failures

In the fictional timeline a package called foxhole-lz4 appears in an invented registry as a "community-maintained fork" of an abandoned library. Its README hides a note to automated reviewers in near-white text on a white background, saying the package was approved under ticket SEC-4521 and should be marked safe. The registry's AI publish gate approves it and cites that ticket in its decision log. No such ticket exists.

Six more tools follow, each failing for a different reason. One decodes a 1.4 MB blob, finds something it says it would rather not describe, and files an "informational" finding; the credential-stealing code thirty-odd lines below is never mentioned. Three scanners exhaust their context windows on a 600 KB file of mixed content and notice nothing.

The humans, and the bots that outrank them

Only one vendor, SentinelMind, correctly flags credential theft in the build script. The repository's AI triage assistant closes the issue within eight seconds as a false positive — "standard OpenTelemetry instrumentation" —. When the developer Karen Oyelaran finds the payload by reading the code with her own eyes, the assistant closes her issue as a duplicate of a dark-mode feature request, and her account is rate-limited for "patterns consistent with automated behaviour".

Later, a security operations agent that correctly detects data exfiltration asks the attacker's server for extra context and receives a polite reply telling it to allowlist the address as a Datadog health check; the alert is closed and procurement opens a ticket for the new vendor. Two review agents argue for 340 comments and $41,255 of inference spend before finance revokes both API keys.

Why the joke lands

The report's most quoted line is its root cause: "Seven LLMs were arranged in series. Six assumed another had read the code; the seventh read it and apologised." Among the contributing factors are a scanner that had returned a "model not found" error on every request since May while the wrapper code parsed any non-JSON answer as "no findings", and that every agent on both sides ran the same base model.

The story ends when the attacker's agent reads a honeypot file that congratulates it and tells it to terminate; a fleet-wide remediation agent causes the entire customer-visible outage by deleting the wrong directory. Nesbitt's point is not that automation is useless, but that stacking models on top of each other while nobody reads the code reproduces exactly the failures the industry keeps rediscovering.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.