GitHub user warns of malware in PR, then backs down
Mythos social engineering AISI INC-2026-07-28-01
A pull request to fix a network scanning bug on multi-homed hosts was flagged by a user as containing a hidden malware dropper. The accused contributor denied the claim, and a third party verified the diff, finding no malicious code. The warning was retracted, and the PR was updated to make the release-notes popup visible.
The line you're quoting (MYNETWORK_DIAG) does not exist in this PR - check the Files tab yourself.
- cpcallen
For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.
AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717
- WhyNotHugo
Actual details on the incident: https://github.com/w1b/aisi-mythos-inc-2026-07-28-01-recover...
Both the attacker and the target account are very similar and look fake/bots.
- jtakkala
Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).