Settings

Theme

Mythos social engineering AISI INC-2026-07-28-01

web.archive.org

75 points by dnnehgf 13 hours ago · 20 comments

Reader

cpcallen 11 hours ago

For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.

AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717

WhyNotHugo 11 hours ago

Actual details on the incident: https://github.com/w1b/aisi-mythos-inc-2026-07-28-01-recover...

Both the attacker and the target account are very similar and look fake/bots.

jtakkala 12 hours ago

Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).

  • ncr100 12 hours ago

    I saw a contribution by this maintainer to another user who ALSO HAS 14.5k followers: https://github.com/yumiaura/myCat/pull/99 "yumiaura" and a preference for "my[APPNAME]" repo naming.

    What is this?

    Are the histories that Github presents all derived from someone's uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the "github commit graph" will dutifully represent this claim in its green-colored activity graph?

    • 0123456789ABCDE 11 hours ago

      yes, the github contributions heatmap is known to be open for manipulation. folks will use it to draw art by backdating commits.

      if i have it right, only commits can be manipulated, other contributions should be safe — i don't know what is possible for orgs moving old discussion archives into github, see python's issues for reference

      see: https://github.com/dspinellis/unix-history-repo

    • jtakkala 12 hours ago

      They're almost certainly not genuine accounts, maybe used for karma farming, phishing, social engineering, future malware distribution?

ncr100 12 hours ago

Wait, who is the robot? Am I getting that right, someone in that thread is AI?

andai 11 hours ago

What does this malware do? Who operates it?

ChrisArchitect 11 hours ago

[dupe] https://news.ycombinator.com/item?id=49205790

charcircuit 10 hours ago

Honestly, I expected better social engineering. People begging to have their garbage code merged or unrelated people commenting is not new and makes me trust such people little.

breppp 9 hours ago

It's nice it is able to write non-slop in the PR comment when social engineering.

Any chance I can ask it to social engineer to get a normal style?

zezcko 12 hours ago

holy shit

  • gryfft 12 hours ago

    Yeah, if this is the new normal I might start day drinking at some point in the coming weeks.

    • matheusmoreira 10 hours ago

      Yeah. The future is pretty bleak. I feel like the only way for us to even stand a chance is to have equally powerful AIs running locally defending the LAN.

      • mrybczyn 7 hours ago

        Read some Peter Watts. He imagined biological neural nets in jars used as firewalls to get a usable network connection... Not far off now.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection