Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
1–10 of 41 posts
Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#2Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#3One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#4What, exactly, are the consequences of these companies doing cyberattacks against random people? One person does it, they get bullied by the government into suicide, a company worth trillions does it and they get government contracts?
“…during a UK government cybersecurity evaluation.”
Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#5Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#6Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least serve some purpose
Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#7Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#8“Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.” Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least ser…
Seems like they might want to do something about that just for comments.
Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
#9You don't say "a car ran over someone" - it was the driver. Here's similar.
I'm really disgusted by this language of lack of responsibility