8 comments

  • cpcallen1 hour ago
    For anyone who, like me, wasn&#x27;t sure what&#x27;s going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.<p>AISI has published a report about the incident which was preciously discussed on HN: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49175717">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49175717</a>
  • WhyNotHugo1 hour ago
    Actual details on the incident: <a href="https:&#x2F;&#x2F;github.com&#x2F;w1b&#x2F;aisi-mythos-inc-2026-07-28-01-recovered-pr" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;w1b&#x2F;aisi-mythos-inc-2026-07-28-01-recover...</a><p>Both the attacker and the target account are very similar and look fake&#x2F;bots.
    • dnnehgf1 hour ago
      yeah, this being one component of the aisi incidents described here: <a href="https:&#x2F;&#x2F;cdn.prod.website-files.com&#x2F;663bd486c5e4c81588db7a1d&#x2F;6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf" rel="nofollow">https:&#x2F;&#x2F;cdn.prod.website-files.com&#x2F;663bd486c5e4c81588db7a1d&#x2F;...</a>
  • jtakkala2 hours ago
    Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
    • ncr1001 hour ago
      I saw a contribution by this maintainer to another user who ALSO HAS 14.5k followers: <a href="https:&#x2F;&#x2F;github.com&#x2F;yumiaura&#x2F;myCat&#x2F;pull&#x2F;99" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;yumiaura&#x2F;myCat&#x2F;pull&#x2F;99</a> &quot;yumiaura&quot; and a preference for &quot;my[APPNAME]&quot; repo naming.<p>What is this?<p>Are the histories that Github presents all derived from someone&#x27;s uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the &quot;github commit graph&quot; will dutifully represent this claim in its green-colored activity graph?
      • 0123456789ABCDE1 hour ago
        yes, the github contributions heatmap is known to be open for manipulation. folks will use it to draw art by backdating commits.<p>if i have it right, only commits can be manipulated, other contributions should be <i>safe</i> — i don&#x27;t know what is possible for orgs moving old discussion archives into github, see python&#x27;s issues for reference<p>see: <a href="https:&#x2F;&#x2F;github.com&#x2F;dspinellis&#x2F;unix-history-repo" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;dspinellis&#x2F;unix-history-repo</a>
      • jtakkala1 hour ago
        They&#x27;re almost certainly not genuine accounts, maybe used for karma farming, phishing, social engineering, future malware distribution?
  • ncr1001 hour ago
    Wait, who is the robot? Am I getting that right, someone in that thread is AI?
    • Erem1 hour ago
      I…I think there are no humans in that thread. Maybe only sinan-can-demir.
    • mekael1 hour ago
      I&#x27;m 99.9% sure that everyone is AI in that thread.
  • andai1 hour ago
    What does this malware do? Who operates it?
  • ChrisArchitect47 minutes ago
    [dupe] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49205790">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49205790</a>
  • zezcko2 hours ago
    holy shit
    • gryfft2 hours ago
      Yeah, if this is the new normal I might start day drinking at some point in the coming weeks.
      • matheusmoreira14 minutes ago
        Yeah. The future is pretty bleak. I feel like the only way for us to even stand a chance is to have equally powerful AIs running locally defending the LAN.