Fedora maintainers and Red Hat engineer Adam Williamson raised concerns that contributor Nathan Giovannini used suspected AI-generated bug reports and package submissions as part of a broader pattern of inauthentic activity. The allegations drew added scrutiny because they echoed ecosystem fears after the xz backdoor case: maintainers said multiple GitHub accounts appeared linked to the same person, profile and contact details were reused, and several reports and code changes showed signs of low-quality or machine-generated content intended to build trust inside the project.
Fedora reviewed bug reports and package changes tied to the contributor, closing some issues as NOTABUG and examining modifications affecting projects including Anaconda, osc, lxqt-policykit, gwenview, and easyeffects. At least one Anaconda change was merged into version 45.5 and later reverted in 45.6, while Fedora maintainers said access was disabled or removed after the concerns surfaced, though they also noted that not every allegation had been definitively proven.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
As part of the review, Fedora maintainers determined that some of the reported issues did not represent valid bugs and closed them as NOTABUG.
After the concerns were raised, Fedora maintainers disabled or removed access associated with the contributor while reviewing the suspicious activity.
Maintainers reviewed multiple bug reports, package changes, and GitHub accounts tied to the contributor, noting reused contact details, email patterns, and low-quality or suspicious submissions affecting projects including osc, lxqt-policykit, gwenview, and easyeffects.
Red Hat engineer Adam Williamson raised concerns about Nathan Giovannini's bug reports and package contributions, saying they appeared AI-generated or otherwise inauthentic and could reflect coordinated behavior.
The suspicious Anaconda-related change that had shipped in version 45.5 was later reverted in Anaconda 45.6.
A change attributed to the suspicious contribution set was merged and appeared in Anaconda 45.5 before later scrutiny. The references identify this as one of the changes that had already landed.
The references state that Nathan Giovannini had been involved with Fedora since 2016, including participation in the Fedora Infrastructure Team.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
lists.fedoraproject.org
Open sourcelists.fedoraproject.org
Open sourcelists.fedoraproject.org
Open sourcelists.fedoraproject.org
Open sourcelists.fedoraproject.org
Open sourcelists.fedoraproject.org
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.