The risk is "materially understated", researchers are saying as passwords and critical data can be exfiltrated.
When (and why) does AI coding flip from promising to a security nightmare? Let's look under the coding hood.
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.