I am convinced we are on the verge of the first "AI agent worm". This looks like the closest hint of it, though it isn't it quite itself: an attack on a PR agent that got it to set up to install openclaw with full access on 4k machines grith.ai/blog/clinejection-whe

But, the agents installed weren't given instructions to *do* anything yet.

Soon they will be. And when they are, the havoc will be massive. Unlike traditional worms, where you're looking for the typically byte-for-byte identical worm embedded in the system, an agent worm can do different, nondeterministic things on every install, and carry out a global action.

I suspect we're months away from seeing the first agent worm, *if* that. There may already be some happening right now in FOSS projects, undetected.

I wrote a blogpost on this: "The first AI agent worm is months away, if that" dustycloud.org/blog/the-first-

People who are using LLM agents for their coding, review systems, etc will probably be the first ones hit. But once agents start installing agents into other systems, we could be off to the races.

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.coop/users/cwebber/statuses/116178175613880782 on your instance and quote it. (Note that quoting is not supported in Mastodon.)