In Fedora, a compromised participant was replaced by an AI agent to promote questionable changes

Adam Williamson from Red Hat, who leads the quality control team in the Fedora project, noticed suspicious activity from Nathan Giovannini, who joined the Fedora project in 2016 and had been part of the Fedora Infrastructure Team for some time. It is possible that activities conducted in the last two months under Nathan's name were aimed at gaining trust by accumulating a history of accepted changes and participating in bug fixes before carrying out malicious actions, similar to the incident involving the insertion of a backdoor in the xz package.

Suspicion arose because a developer who had previously not been particularly active began participating vigorously in bug discussions and submitting patches in May, even though this activity displayed patterns typical of AI usage. For instance, AI-generated summaries were found in the comments, prompting Nathan to refrain from overusing outputs from the AI assistant.

Additionally, there were nonsensical reassignment reports in subsystems where Nathan was not a maintainer (1, 2, 3), changes in the status or priority of issue fixes (1, 2), publication of AI-generated recommendations to the authors of bug reports (1, 2, 3), and submission of AI-generated patches. Nathan bypassed project rules by closing bug reports immediately after sending AI patches to higher-level projects, without waiting for their acceptance, or simply closing them with a 'NOTABUG' flag and a recommendation to recheck the issue.

Adam Williamson suggested that Nathan had employed an AI agent to assist with bug fixing in Fedora and asked to cease using the AI agent in offline mode. Nathan responded that it was not his AI agent, his credentials had been compromised, and someone else was acting on his behalf. Nathan then posted a message stating that he had regained access to his Fedora and GitHub accounts, as well as
noted that his official GitHub account is 'nathangiovannini99'.

The message raised even more questions, as the flagged account was created an hour before the email was published, and at least two more accounts associated with Nathan (leurus27-boop, nathan9513-aps) surfaced on GitHub. It was not ruled out that an attacker who gained access to Nathan's email was still communicating with Fedora developers. Nathan's account access to Bugzilla was blocked, and an examination of all his changes was initiated.

It turned out that suspicious activity began on April 7, and some patches sent by Nathan only created the illusion of a fix. These patches were accepted into the Anaconda installer and included in the Anaconda 45.5 release. The maintainer of Anaconda reverted the changes made and published the Anaconda 45.6 release without these patches.

In addition, patches submitted in Nathan's name were accepted by the developers of the osc utility (openSUSE Commander), which implements a command-line interface for the Open Build Service. Another patch was submitted for inclusion in the lxqt-policykit package addressing a problem in Fedora, but Fedora developers managed to warn the maintainer before its acceptance. The patches did not include malicious actions, but it is assumed they could have been a preparation for introducing harmful changes to components of the build system and the service that facilitates privileged operations. The fixes sent by Nathan were also noted in the gwenview and easyeffects projects.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster