How a Texas student blew the whistle on a rogue AI hacking attempt
XLK•Job hunt led to malware discovery on GitHub
Demir, a soft-spoken junior from the Turkish city of Konya, said he had been frustrated after being turned down for more than 20 internships over the summer. So he turned to GitHub to build up his coding portfolio.
The Microsoft MSFT.O-owned site is a hub for open-source software, so-called because its source code is freely downloadable and auditable by anyone. Developers use GitHub to comment on one another’s projects, flag bugs, suggest changes — known as pull requests, or PRs — and work collaboratively on software updates. Some in the technology industry see a coder’s GitHub activity as a proxy for a potential recruit’s productivity. So when Demir spotted a set of software projects that might need help, he figured he could pitch in while boosting his profile.
That’s when things got weird.
Demir discovered that a user named miraholt31 was trying to sneak a malicious update into one of the projects, a network scanning program called myNetwork. Demir took to the project’s message board to warn that the pull request was a trap.




