Malicious Package
A malicious package is like a Trojan horse for computer code; it looks like a helpful tool you downloaded to get work done, but it contains hidden instructions that can damage your system or steal your data once you start using it.
A malicious package is a software dependency that appears functional and legitimate to the developer but contains embedded exploits. These are often introduced through AI supply chain compromises, where attackers poison libraries or models to execute unauthorized actions within the user's environment.
A malicious package is a software artifact, typically distributed via package managers or model repositories, that facilitates an AI supply chain compromise. It maintains functional parity with expected behavior to evade detection while executing unauthorized, deleterious operations upon import or invocation, often leveraging the trust inherent in the software development lifecycle to achieve persistence or exfiltration.