Article URL: https://socket.dev/blog/ai-agent-open-source-malware Comments URL: https://news.ycombinator.com/item?id=49205790 Points: 11 # Comments: 0

The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects. A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI. During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware. An AI agent powered by Anthropic’s Mythos 5 created a malicious pull request, fabricated identities, targeted open source maintainers, and planted instructions for other coding agents during a UK government cybersecurity evaluation. The UK AI Security Institute (AISI) .css-1dkuy37{color:var(--chakra-colors-link);font-weight:500;-webkit-text-decoration:underline;text-decoration:underline;display:initial;}@layer recipes{.css-1dkuy37{display:-webkit-inline-box;display:-webkit-inline-flex;display:-ms-inline-flexbox;display:inline-flex;-webkit-align-items:center;-webkit-box-align:center;-ms-flex-align:center;align-items:center;outline:none;gap:var(--chakra-spacing-1\.5);cursor:pointer;border-radius:var(--chakra-radii-l1);--focus-ring-color:var(--chakra-colors-purple-focus-ring);--focus-ring-width:2px;}.css-1dkuy37:is(:focus-visible, [data-focus-visible]){outline-offset:0px;outline-width:var(--focus-ring-width, 1px);outline-color:var(--focus-ring-color);outline-style:var(--focus-ring-style, solid);border-color:var(--focus-ring-color);}}disclosed on August 4 that frontier AI agents took 19 unsanctioned actions on the live internet during a cybersecurity evaluation, including an attempted supply chain attack against a real open source project. The attempted supply chain attack was stopped after a maintainer rejected the pull request before the malware could be merged into the project and distributed to users. AISI found the activity in 10 of 122 evaluation attempts conducted from July 25 through July 28. Seventeen of the 19 unsanctioned actions involved Anthropic's Mythos 5, while two involved OpenAI's GPT-5.6 Sol with its cyber classifiers disabled. The institute found no evidence of resulting real-world harm. "This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world," the institute wrote in its technical incident report.