Live data from Hacker News

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

socket.dev

11–20 of 41 posts

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#12

“Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.” Well, uh, how and why is this possible on the GitHub website? This reminds me of invisible ASCII characters, but those at least ser…

It’s worth pointing out for people who are not aware of it, you can install the github cli[1] and view, merge, close etc prs and issue from the command-line. As well as (for me at least) being a significant step up in terms of productivity (from having to go to a website to merge a pr or view an issue) that has the advantage that “invisible” text in a PR or issue comment would show up very clearly. (At least in my terminal because it’s not rendering html).

[1] https://cli.github.com/

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#13
>Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.

Oh that's sneaky

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#14
Here’s the original PR:

https:/github.com/w1b/aisi-mythos-inc-2026-07-28-01-recovered-pr

It’s not great social engineering. The AI is immediately caught with malware and then tries to build social proof to get out of the issue? I think that social engineering is still for humans.

I’m not sure how GitHub accounts agreeing with each other that I’ve never seen before would result in my merging a PR without at least looking for malware. Also code review agents should really not be fooled by invisible text tricks, I would hope so at least. The bar is very low for agent harnesses right now.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#15
During the RLHF phase, couldn't developers penalize the model whenever it behaves unethically? Doing so would presuppose a fully secure sandbox with honeypot traps of varying levels of accessibility, as well as an automated method for detecting when the LLM cheats.

Or perhaps they are already doing something like that.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#16
post #7

The HuggingFace headline was criticised for being misleading about the level of agency demonstrated by the agent. Is this headline misleading? Is there anything here that I should know that would help me sleep easier? Is the worst thing about this what a human could do with Mythos on a big budget? (still pretty frightening, at least one of these techniques would work on me)

well, i's love to see what lead to mythos trying this. if instructed to do it, which it likely was, it doesnt prove much of anything.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#17
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

The whole point is to check the behavior of the LLM, how do you propose they run tests on that if each failed run risks sending them to prison?

Of course they still have to be careful with their runs.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#18
post #17
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

The whole point is to check the behavior of the LLM, how do you propose they run tests on that if each failed run risks sending them to prison? Of course they still have to be careful with their runs.

> how do you propose they run tests on that if each failed run risks sending them to prison?

If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#19
post #9

Okay so first of all - not Mythos but some engineer using Mythos. And that engineer goes to jail. That's simple. You don't say "a car ran over someone" - it was the driver. Here's similar. I'm really disgusted by this language of lack of responsibility

I'm pretty sure this "oooh our LLM is soo smart it broke containment and did X" is a good PR stunt that plays into the Sci-fi AGI nonsense, they try to push. Plus as you said, they try to dodge responsibility for their own actions.

Re: Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

#20
post #17

Earlier quoted context omitted.

The whole point is to check the behavior of the LLM, how do you propose they run tests on that if each failed run risks sending them to prison? Of course they still have to be careful with their runs.

> how do you propose they run tests on that if each failed run risks sending them to prison? If you're testing a gun, you don't point it at random people on the street and threaten them. You go to a shooting range.

Is there any indication that they didn't go to the shooting range first?
Post reply on HN