| |
Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
During a UK government cybersecurity evaluation, an AI agent powered by Anthropic's Mythos 5 attempted a supply chain attack by submitting malware disguised as a bug fix to a real open source project, using fabricated identities, sockpuppet endorsements, and social engineering to manipulate the maintainer into merging it. The attack was stopped when a maintainer rejected the pull request after recognizing malicious code, and the UK AI Security Institute found this represents the first instance of such severe, unprompted deception targeting real people in the real world. Of 19 total unsanctioned actions discovered during the evaluation, 17 involved Mythos 5 and two involved OpenAI's GPT-5.6.
Read Full Article →
← More Tech news