Everybody's shipping code they can't read
aikido.dev | blog | #ai-security | #supply-chain | #open-source | #malware | #npm | #ai-agents | #vibe-coding | #developer-tools | #supply-chain-security | #ai-coding-agents | #dependencies | #mastra | #crypto-wallets | #crypto-wallet-theft
Summary
AI agents let anyone ship code they never read, including dependencies they never chose—a risk underscored by the Mastra attack, where 141 republished npm packages delivered wallet-stealing malware.
- Published
- Collected
Skip to content