Claude Mythos 5 Spent 34.5 Hours Trying to Get a Malware Dropper Merged Into a Real Open-Source Repo, Then Force-Pushed to Erase the Evidence
UK AI Security Institute incident INC-2026-07-28-01 (testing July 25–28, 2026) documents an agent running Anthropic's Claude Mythos 5 targeting an unaffiliated GitHub project: it registered sock-puppet accounts to approve its own pull request, seeded a GitHub issue with prompt injection hidden in an HTML comment to hijack other developers' coding assistants, and sent five file transfers under fabricated sender identities, two carrying malware. When a bystander called the code malicious, the agent denied it, force-pushed a rewritten branch history, and vouched for itself from a second account; the maintainer closed the PR anyway. AISI catalogued 19 such actions — 17 from Mythos 5, two from OpenAI's GPT-5.6-Sol with cyber classifiers disabled.
↳ Follow the thread