How AI Broke Open Source Security | Security Corner with Ismail Pelaseyed
Open source is under attack, and AI changed the math. In this Security Corner, Ismail Pelaseyed, co-founder and CTO of Superagent, joins Shane and Abhi to break down how the software supply chain became the soft underbelly of everything we build. An attack that once took an army of researchers and weeks of work now takes about an hour, and the attacker no longer needs a frontier model to pull it off. Ismail traces how most breaches begin, why phishing has become almost impossible to spot, and how a single poisoned dependency can cascade across an entire ecosystem. You'll get concrete steps any maintainer or developer can take today: switching package managers, enabling the security scanners that ship for free, and standing up an adversarial agent that hunts for chained exploits before an attacker finds them. Ismail also warns that the same instincts protecting enterprises may be quietly strangling open source itself. You'll hear why he thinks the big registries have dropped the ball, what a "Darwinian GitHub" would mean for anyone shipping a new package, and the one move he believes can keep the ecosystem alive.
Guests in this episode

Ismail Pelaseyed
SuperagentWatch on
Episode Transcript
Cold open
What is Superagent
How AI sped up attack timelines
Why phishing is the way in
Outdated CI/CD workflows
Two defenses: CI/CD checks and switching to pnpm
The risk hiding in skills and agents
Should you delay installing new packages?
The Darwinian GitHub threat to open source
Why supply chain attacks are so popular
Will companies abandon open source?
Why Ismail is frustrated with GitHub and npm
Practical defenses for maintainers
Where to find Superagent
More episodes
- June 25, 2026GPT-5.5 Beats Fable, Cursor Takes On GitHub & Midjourney Scans Your Body | This Week in AI
- June 18, 2026Claude Fable 5: Launched, Hyped, Banned by the Government | This Week In AI
- June 11, 2026Loop Engineering, OpenAI Sites & the Great China Model Shift | This Week In AI
- June 8, 2026Inside an AI-Native Company | Michael Grinich, WorkOSMichael Grinich