AI has upended the foundation of open source security, and commercial open source applications must close their code to protect sensitive data.
Source code is no longer the attack surface. The binary is. And most security teams aren’t even looking at it.
A researcher flagged the issue on 31 March 2026, and the code has since been archived on multiple public repositories, raising fresh questions about the company's software release practices.