Printed from Production AI Institute public record

https://www.productionai.institute/graph/entities/aiid-alibaba

Production AI Institute · Public recordRecord
Production AI Institute
Briefing
Briefing

Today's public AI briefing: what changed, what went wrong, and what the evidence says.

Open Briefing →
Today's AI briefingThe daily record of what changed and broke.Public record explorerSearch every incident, entity, and source.
Check
Check

Inspect tools, incidents, and data-use disclosures against the public record.

Open Check →
Check an AI toolWhat a tool actually does with your data.Run exposure checkTest your own stack against the record.Data-use indexDisclosures across the major AI tools.Incident registryDocumented production AI failures.
The Lab
The Lab

Independent research instruments: model and agent scorecards, moral-reasoning evals, and ecosystem assessments.

Open The Lab →
The LabHow frontier models and agents actually perform.AI Morality CompassTest models on hard moral cases.Agent readinessIs the agent ecosystem production-ready?Ecosystem assessmentsIndependent reviews of the AI stack.Model & agent evalsOpen evaluations and their results.Research libraryEvidence-led analysis and briefings.
Learn
Learn

The open standard, the tools built on it, and the research that interprets the record.

Open Learn →
The FrameworkThe open production safety framework, explained.AI Adoption GuideFive stages from gated access to safe autonomy.Production AI Deployment GuideBuild a governed production system on Microsoft or AWS.Five-Year Automation RoadmapSequence enterprise capability, controls, and value.WorkflowOS · open sourceBuild governed AI workflows.Workflow libraryReady-made governed workflows.InsightsResearch articles on the record.
Act
Act

Turn uncertainty into public evidence: ask, disclose, build evidence, or correct.

Open Act →
Ask for disclosureRequest a public data-use answer.Submit a correctionFlag something wrong or missing on the record.Save a watchTell PAI what to keep current for you.
Method
Method

How the public record is made, governed, corrected, cited, and kept independent.

Open Method →
How records are madeSourcing, review, and correction.
Check an AI tool
Record
Record
Check an AI tool
Production AI Institute public record · alibaba · observed 2025-10-04
← Public record explorer
Reading room view →
organisation
Production AI public record - EditorialMethod →

alibaba

alibaba - organisation named in the AI Incident Database harm index.

Confidence
70%
Sources
15
Events
5
Observed
observed 297d ago
alibaba

What changed

Ukraine's CERT-UA and Cato CTRL reported LAMEHUG, the first known malware to integrate a large language model (Qwen2.5-Coder-32B-Instruct via Hugging Face) for real-time command generation. Attributed with moderate confidence to APT28 (Fancy Bear), the malware reportedly targeted Ukrainian officials through phishing emails. The LLM is reported to have dynamically generated reconnaissance and data-exfiltration commands executed on infected systems.

  • Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear)https://www.catonetworks.com/blog/cato-ctrl-threat-research-analyzing-lamehug/
  • Кібератаки UAC-0001 на сектор безпеки та оборони із застосуванням програмного засобу LAMEHUG, що використовує LLM (вели…https://cert.gov.ua/article/6284730
  • AI Incident Database - Incident 1220https://incidentdatabase.ai/cite/1220/

Timeline

  1. 4 Oct 2025LAMEHUG Malware Reportedly Integrates Large Language Model for Real-Time Command Generation in a Purported APT28-Linked Cyberattack
    Incident82%
    • Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear)https://www.catonetworks.com/blog/cato-ctrl-threat-research-analyzing-lamehug/
    • Кібератаки UAC-0001 на сектор безпеки та оборони із застосуванням програмного засобу LAMEHUG, що використовує LLM (вели…https://cert.gov.ua/article/6284730
    • AI Incident Database - Incident 1220https://incidentdatabase.ai/cite/1220/
  2. 26 Aug 2025Reported Public Exposure of Over 100,000 LLM Conversations via Share Links Indexed by Search Engines and Archived
    Incident82%
    • ChatGPT Chats Were Indexed Then Removed From Search but Still Remain Onlinehttps://growtika.com/chatgpt-shared-chats-seo-indexing-privacy-leak/
    • Leaking Secrets with AI: The Hidden Risks of ChatGPT’s Share Featurehttps://www.toreon.com/leaking-secrets-with-ai-the-hidden-risks-of-chatgpt-share-feature/
    • AI Incident Database - Incident 1186https://incidentdatabase.ai/cite/1186/
  3. 20 Apr 2025Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers
    Incident82%
    • AI hallucinates software packages and devs download them – even if potentially poisoned with malwarehttps://www.theregister.com/2024/03/28/ai_bots_hallucinate_software_packages/
    • AI code helpers just can't stop inventing package nameshttps://www.theregister.com/2024/09/30/ai_code_helpers_invent_packages/
    • AI Incident Database - Incident 731https://incidentdatabase.ai/cite/731/
  4. 6 Apr 2025LLM Scrapers Allegedly Target Multiple Open Source Projects Disrupting the FOSS Ecosystem
    Incident82%
    • FOSS infrastructure is under attack by AI companieshttps://thelibre.news/foss-infrastructure-is-under-attack-by-ai-companies/
    • Open source devs say AI crawlers dominate traffic, forcing blocks on entire countrieshttps://arstechnica.com/ai/2025/03/devs-say-ai-crawlers-dominate-traffic-forcing-blocks-on-entire-countries/
    • AI Incident Database - Incident 1001https://incidentdatabase.ai/cite/1001/
  5. 17 Aug 2022Chinese Tech Firms Allegedly Developed Facial Recognition to Identify People by Race, Targeting Uyghur Muslims
    Incident82%
    • Surveillance group exposes disturbing Huawei patent for AI-powered Uighur detectionhttps://thenextweb.com/news/surveillance-group-exposes-disturbing-huawei-patent-for-ai-powered-uighur-detection
    • Alibaba ‘dismayed’ by its cloud unit’s ethnicity detection algorithm – TechCrunchhttps://techcrunch.com/2020/12/17/alibaba-ethnic-minority-algorithm/
    • AI Incident Database - Incident 107https://incidentdatabase.ai/cite/107/

PSF mapping

No PSF domains are mapped to this entity in the current public record.

Source trail (15)

secondary · checked 9 July 2026

↗

secondary · checked 9 July 2026

↗

secondary · checked 9 July 2026

↗

secondary · checked 9 July 2026

↗

secondary · checked 9 July 2026

↗

secondary · checked 4 Oct 2025

↗

secondary · checked 4 Oct 2025

↗

secondary · checked 26 Aug 2025

↗

secondary · checked 25 Aug 2025

↗

secondary · checked 20 Apr 2025

↗

secondary · checked 6 Apr 2025

↗

secondary · checked 25 Mar 2025

↗

secondary · checked 16 June 2024

↗

secondary · checked 17 Aug 2022

↗

secondary · checked 30 June 2021

↗

Related records

Connected entities

standardPSF D3 — Data ProtectionstandardPSF D4 — ObservabilitystandardPSF D5 — Deployment SafetystandardPSF D8 — Vendor Resilience

Original public page: Open original record

Open in record explorer →
Cite this record

"alibaba." https://www.productionai.institute/graph/entities/aiid-alibaba (observed 2025-10-04; retrieved 2026-07-28). PAI.

Share on XShare on LinkedInCitation guide →
Public record

This record is maintained by PAI and free to cite. If something is wrong or missing, tell us. Corrections and source suggestions keep the record honest.

Share the record
Share on XShare on LinkedIn
Follow policy changes ->Save a watch ->Submit a correction
Records are free to cite. citation guidance.
AI risk intelligence

Track what changed, read the weekly brief, and follow the public evidence record - the operator loop for production AI risk.

Live risk watch →AI risk brief →Save a watch →Public record →
PAI
Production AI Institute

The public record and operating memory for production AI: what changed, what broke, and what the evidence says.

WorkflowOS · open source (MIT)
Navigate
Briefing
OverviewToday's AI briefingPublic record explorer
Check
Check an AI toolRun exposure checkData-use indexIncident registry
The Lab
The LabAI Morality CompassAgent readinessEcosystem assessmentsModel & agent evalsResearch library
Learn
The FrameworkAI Adoption GuideProduction AI Deployment GuideFive-Year Automation RoadmapWorkflowOS · open sourceWorkflow libraryInsights
Act
Ask for disclosureSubmit a correctionSave a watch
Method & trust
How records are madeCorrectionsHow to citeContact
© 2026 Production AI Institute · CC BY 4.0
AboutPrivacyTermsSecurityGovernanceIndependence