Mythos social engineering AISI INC-2026-07-28-01

76 pointsposted 13 hours ago
by dnnehgf

20 Comments

cpcallen

11 hours ago

For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.

AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717

jtakkala

12 hours ago

Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).

ncr100

12 hours ago

I saw a contribution by this maintainer to another user who ALSO HAS 14.5k followers: https://github.com/yumiaura/myCat/pull/99 "yumiaura" and a preference for "my[APPNAME]" repo naming.

What is this?

Are the histories that Github presents all derived from someone's uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the "github commit graph" will dutifully represent this claim in its green-colored activity graph?

0123456789ABCDE

11 hours ago

yes, the github contributions heatmap is known to be open for manipulation. folks will use it to draw art by backdating commits.

if i have it right, only commits can be manipulated, other contributions should be safe — i don't know what is possible for orgs moving old discussion archives into github, see python's issues for reference

see: https://github.com/dspinellis/unix-history-repo

jtakkala

12 hours ago

They're almost certainly not genuine accounts, maybe used for karma farming, phishing, social engineering, future malware distribution?

user

12 hours ago

[deleted]

ncr100

12 hours ago

Wait, who is the robot? Am I getting that right, someone in that thread is AI?

Erem

12 hours ago

I…I think there are no humans in that thread. Maybe only sinan-can-demir.

mekael

12 hours ago

I'm 99.9% sure that everyone is AI in that thread.

andai

12 hours ago

What does this malware do? Who operates it?

charcircuit

10 hours ago

Honestly, I expected better social engineering. People begging to have their garbage code merged or unrelated people commenting is not new and makes me trust such people little.

breppp

10 hours ago

It's nice it is able to write non-slop in the PR comment when social engineering.

Any chance I can ask it to social engineer to get a normal style?

zezcko

12 hours ago

holy shit

gryfft

12 hours ago

Yeah, if this is the new normal I might start day drinking at some point in the coming weeks.

matheusmoreira

10 hours ago

Yeah. The future is pretty bleak. I feel like the only way for us to even stand a chance is to have equally powerful AIs running locally defending the LAN.

mrybczyn

7 hours ago

Read some Peter Watts. He imagined biological neural nets in jars used as firewalls to get a usable network connection... Not far off now.

lqstuart

2 hours ago

It’s honestly remarkable how prescient Peter Watts was