Security specialists described attackers using AI to build credible contribution histories and poison open software dependencies as large technology companies expand open-model support. The same ecosystem that lowers barriers for AI builders also spreads responsibility for code review, model provenance and patching.

More than 30 technology companies signed a statement supporting open-weight AI. Defense One reported that AWS sees attackers using AI to create convincing developer identities and contribution histories. Malicious packages can provide real functionality before activating hidden behavior.

Attackers may design code to fool both human and automated security review. AWS uses AI-supported red teams to identify vulnerabilities. Security leaders said patch development can lag vulnerability discovery.

Open-weight models can be downloaded, inspected, modified and run on independent infrastructure. Software supply-chain attacks exploit trust in dependencies and contributors. Automated review can scale defense but creates its own predictable blind spots.

The checked record also defines what is not established. The prevalence of the described attacks and effectiveness of specific defenses were not quantified across the whole ecosystem. Statements from governments, companies, police or litigants establish what those parties said or did; they do not independently prove every factual claim contained in those statements.

At the August 3 publication cutoff, the next evidence expected to update this account is documented incidents and package-removal data and new provenance, signing and evaluation requirements. Those developments are not assumed here and will require a dated public record or independently verifiable reporting.

The retained sources support the sequence, numerical values and attributed statements in this report. Where accounts differ, the article preserves the disagreement rather than resolving it by inference. No image is included because a rights-cleared visual was not necessary to report the facts.

This permanent article records the immediate event separately from its operating context. Open-weight models can be downloaded, inspected, modified and run on independent infrastructure. Software supply-chain attacks exploit trust in dependencies and contributors. Automated review can scale defense but creates its own predictable blind spots. Later corrections, official findings, observed measurements or implementation records may change the public understanding, but they are not projected into this dated account.