Void Linux removed 113 packages from its repository after an investigation into AI-assisted changes by developer Andrea Brancaleoni, who subsequently left the project. Affected packages included alacritty, docker-cli, etcd, Kubernetes, Terraform, Vagrant, and virt-manager; the review focused particularly on new Go dependencies and build-system changes.
Void Core Team said the questioned patches had been generated with the OpenCode AI agent using the GLM-5.3-flash model. The team found no evidence of an intentional attempt to introduce malicious code, but deemed the changes inappropriate because of quality and correctness concerns, especially in Go-related modifications, and said the developer's access would not be restored.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Andrea Brancaleoni reportedly removed 113 packages from the Void Linux repository and left the project following the dispute. Void Core Team characterized the AI-generated changes as unacceptable and indicated that the developer's account or access would not be restored.
Void Core Team investigated the suspicious modifications after concerns about unsafe or potentially malicious changes. It determined the changes had been generated using the OpenCode AI agent with the GLM-5.3-flash model, while stating it found no evidence of deliberate malicious-code insertion.
Void Linux developer Andrea Brancaleoni submitted package and code changes affecting 113 repository packages, including alacritty, docker-cli, etcd, Kubernetes, Terraform, Vagrant, and virt-manager. The changes included new dependencies and Go-related build or code modifications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.