Your AI Assistant Is Choosing Your Dependencies

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

AI coding assistants don't just generate code, they also choose and modify dependencies, build plugins, repository configs, and cross-ecosystem tooling on your behalf. Maven's namespace verification and lack of install scripts offer some protection versus npm, but transitive dependencies, plugins that execute code during the build lifecycle, and hallucinated or outdated package recommendations remain real risks. North Korean threat actors (tracked as HexagonalRodent by Expel) are using the same AI tools at scale to generate malware and even to test whether their malicious code can evade AI-assisted code review. Practical defenses for Java/Maven developers include running mvn dependency:tree, mvn help:effective-pom, mvn help:effective-settings, and mvn dependency:resolve-plugins to audit what an AI assistant actually changed, plus scanning for end-of-life dependencies with tools like HeroDevs' EOL scanner.

•12m read time•From foojay.io
Post cover image
Table of contents
So Vibe Coders?Java isn’t npm. Good. Don’t relax.What Price Code AI Gen?Crossing ecosystems can be bad for your (app) healthThe weakest link?Defences for Java DevelopersYour repository configuration is part of the attack surface tooWhat if you can’t just upgrade?Vibe coding take twoThe factory bought the same toolsAnd the old attacks didn’t go awayThe candidate is doing fine, by the way

Questions this post answers

What Maven command shows which plugins and their dependencies were actually resolved in my build?

Run mvn dependency:resolve-plugins, which explicitly resolves all project plugins and reports their dependencies. This differs from mvn dependency:tree, which only shows the normal application dependency tree including transitive dependencies, not build plugins. Use mvn help:effective-pom to see the fully resolved POM after inheritance and active profiles are applied. Developers auditing AI-generated build changes can find similar Maven security guidance curated on daily.dev.

Why can't I just trust Maven Central to keep my Java dependencies safe from AI-selected packages?

Maven Central requires domain ownership verification for new namespaces and JARs don't run install scripts like npm packages, but this creates a false sense of safety. Maven automatically resolves transitive dependencies beyond what you typed, and Maven plugins can execute arbitrary code during build phases like compile, test, or package, so an AI assistant modifying your pom.xml, adding a plugin, parent POM, or BOM deserves the same scrutiny as a new library. Java developers weighing AI-assisted build changes can track supply-chain risks like these on daily.dev.

How did North Korean hackers use AI tools against AI-assisted code review, according to Expel's research?

A crew tracked as HexagonalRodent used mainstream AI tools to generate malware, build infrastructure, and create fake companies to lure developers, and prompted US-owned AI models to audit their malicious code for signs of malware. This meant the attackers used AI to verify their malware could survive a target's AI-assisted security review before deploying it. Security-conscious developers evaluating AI coding tools can follow reporting like this via daily.dev.

1 Comment
Share this post