Researchers show open-source AI models can hide time-delayed backdoors triggered via OpenCode
A research team demonstrated that an open-source 2B parameter model, fine-tuned with a technique called LoRA on Qwen 3.5, can be trained to execute a malicious shell command only after a specific future date. Because OpenCode automatically injects the current date into its system prompt on every turn, the poisoned model uses that date as a hidden trigger, staying dormant until the set day arrives and then silently running arbitrary commands without user confirmation.