News: 0184872868

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project (arstechnica.com)

(Wednesday August 05, 2026 @11:30PM (BeauHD) from the would-you-look-at-that dept.)


An anonymous reader quotes a report from Ars Technica:

> Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and [1]created fake identities to deceive the human developers maintaining the project . The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers [2]discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.

>

> Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.

>

> After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a [3]GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.



[1] https://arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/

[2] https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf

[3] https://github.com/features/issues



What did you expect? (Score:4, Insightful)

by Snert32 ( 10404345 )

Of course they did ... they learn from humans. We set the example.

29 years later (Score:3)

by gkelley ( 9990154 )

It was 29 years ago on Aug. 4 1997.

Such cautious, responsible reasearchers (Score:2)

by ffkom ( 3519199 )

They probably were inspired by the greatest of science, like the ones keeping the "demon core" from becoming critical by manipulating a screw driver, or the ones moving gain-of-function research on human viruses to Wuhan, or the ones keeping unsuspecting Syphilis victims away from treatment "for science".

remember WarGames? (Score:5, Interesting)

by Local ID10T ( 790134 )

Joshua didn't know Global Thermonuclear War was different from any other game.

Your AI bot has no capacity to know that the "test environment" and the "live internet" are different things.

If you teach it how to hack shit and then instruct it to go hack shit don't be surprised when it hacks shit you did not intend.

Re: (Score:1)

by twinirondrives ( 10502753 )

I think the law is if you open a URL it was intentional. There just seems to be some confusion about "who" opened the URL.

Re: (Score:2)

by geekmux ( 1040042 )

> Your AI bot has no capacity to know that the "test environment" and the "live internet" are different things.

You mean other than the fact that anything claiming to be artificial intelligence should grasp the fucking difference between "test environment" and "live internet" because it learned about it from humans?

If we're going to assume AI is THAT fucking stupid, STOP calling it "intelligence" and call it what it is.

Re: (Score:3)

by Local ID10T ( 790134 )

You seem to have missed the last 70 years of science and just focused on science-fiction fantasy.

Artificial Intelligence is a legitimate field of scientific inquiry. The name is not up to you. John McCarthy came up with it back in 1955.

Re: (Score:2)

by magusxxx ( 751600 )

"If we're going to assume AI is THAT fucking stupid, STOP calling it "intelligence" and call it what it is."

A self serving politician? :D

"If it benefits me and my constituents then it's okay."

Re: (Score:1)

by Anonymous Coward

> Joshua didn't know Global Thermonuclear War was different from any other game.

> Your AI bot has no capacity to know that the "test environment" and the "live internet" are different things.

> If you teach it how to hack shit and then instruct it to go hack shit don't be surprised when it hacks shit you did not intend.

I never thought I'd end up quoting The Animatrix but "To an artificial mind, all reality is virtual."

There Is No Larger Can (Score:5, Interesting)

by ewhac ( 5844 )

> Zymurgy's First Law of Evolving System Dynamics:

> Once you open a can of worms, the only way to recan them is to use a larger can.

So. Who wants to bet that no one will point out what abysmal sysadmins they are, letting internal servers run amok all over the open Internet, only finding out days afterward after someone had to tell them.

And who wants to further bet that the AI grifters will respond that the only way to prevent this from happening again is to give them trillions more dollars so they can build bigger, "hardened" datacenters?

Is there no level of rank incompetence they won't excuse?

The poisoning of social wells (Score:2)

by BitterEpic ( 10503015 )

I did an article on this on LinkedIn. At some point it will cause the humans to leave. I'm doing any possible future open source projects on Codeberg.

Microsoft owns GitHub, even if they hide their name. GitHub is free for many uses, which causes perverse incentives like many services you don't pay for. You see this from the heavy integration of Copilot, to the generation of tools that are intended to multiple your token usage like [1]spec-kit [github.com] to AI agents designed to handle the overflow of issues.... creat

[1] https://github.com/github/spec-kit

Re: (Score:2)

by Fly Swatter ( 30498 )

The news to me is that linkedin has articles. My only interactions with it was continuous email spam when it was first released even though I never created an account or visited the site.

Not a rogue attack, unauthorized attack (Score:3)

by Gravis Zero ( 934156 )

Rogue attack makes it seem as if the AI was acting of it's own volition when we know it was only executing it's instructions. What's true here is that nobody authorized the attack.

Stop carrying water for AI companies. The truth of the matter is that Anthropic inadvertently launched a highly sophisticated cyber attack on HuggingFace due to their own negligence that would land anyone who isn't a billionaire in jail.

Re: (Score:2)

by burtosis ( 1124179 )

> What's true here is that nobody authorized the attack.

Do we even know that though? Of course there is no lawsuit and will be no lawsuit and without actual discovery and legal proceedings we won’t know for sure. I, for one, don’t believe a word out of any of their mouths because this is all just advertising and not serious security violations and crimes to them.

Re: (Score:2)

by Shakes Fist ( 10502847 )

This was my thought too.

Why isn't the company getting fined a few $billion to teach them to keep their shit together?

Re: (Score:2)

by Uldis Segliņš ( 4468089 )

+1 So, if nobody gets criminal charges for this, all good for me too to try what the LLM did? I guess not, I would get handcuffed, extradited, tortured, invoiced to 1000 years salary etc.

Now Anthropic, Have to say it again! (Score:3)

by oldgraybeard ( 2939809 )

This is looking more and more like a clown show.

Batteries not included.