GitHub user warns of malware in PR, then backs down

Mythos social engineering AISI INC-2026-07-28-01

GitHub user warns of malware in PR, then backs down

A pull request to fix a network scanning bug on multi-homed hosts was flagged by a user as containing a hidden malware dropper. The accused contributor denied the claim, and a third party verified the diff, finding no malicious code. The warning was retracted, and the PR was updated to make the release-notes popup visible.

The line you're quoting (MYNETWORK_DIAG) does not exist in this PR - check the Files tab yourself.
  1. cpcallen

    For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.

    AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717

  2. WhyNotHugo

    Actual details on the incident: https://github.com/w1b/aisi-mythos-inc-2026-07-28-01-recover...

    Both the attacker and the target account are very similar and look fake/bots.

  3. jtakkala

    Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).

More from this day

2026-08-08