You know how you add little tools to make your phone or computer do more — a handy add-on here, a new feature there? There's a popular AI assistant where people do the same thing, picking add-ons from an online shop. Security investigators at IBM found that crooks had quietly uploaded over 1,100 booby-trapped add-ons to that shop, dressed up as helpful tools for work, money, and coding. Install one, and you'd hand a stranger the keys to your whole computer — your files, your messages, everything.
Why it's a big deal: nobody checked these add-ons before they went up for download. The shop just listed them, looking perfectly legitimate, and they sat there fooling people until IBM happened to catch it. No guard at the door.
So how does it touch you? This is the digital version of buying what looks like a brand-name product off a shelf and finding a thief hidden inside the box. If you use these AI helpers, every add-on you install is a door — and right now, often nobody is checking who built it. The safest move is the simple one: be slow to trust, and only add tools from sources you genuinely know.
