Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- holy shitby zezcko
- Yeah, if this is the new normal I might start day drinking at some point in the coming weeks.by gryfft
- It's nice it is able to write non-slop in the PR comment when social engineering.
Any chance I can ask it to social engineer to get a normal style?
by breppp - Honestly, I expected better social engineering. People begging to have their garbage code merged or unrelated people commenting is not new and makes me trust such people little.by charcircuit
- What does this malware do? Who operates it?by andai
- Wait, who is the robot? Am I getting that right, someone in that thread is AI?by ncr100
- I'm 99.9% sure that everyone is AI in that thread.by mekael
- I…I think there are no humans in that thread. Maybe only sinan-can-demir.by Erem
- Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).by jtakkala
- I saw a contribution by this maintainer to another user who ALSO HAS 14.5k followers: https://github.com/yumiaura/myCat/pull/99 "yumiaura" and a preference for "my[APPNAME]" repo naming.
What is this?
Are the histories that Github presents all derived from someone's uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the "github commit graph" will dutifully represent this claim in its green-colored activity graph?
by ncr100 - Actual details on the incident: https://github.com/w1b/aisi-mythos-inc-2026-07-28-01-recover...
Both the attacker and the target account are very similar and look fake/bots.
by WhyNotHugo - yeah, this being one component of the aisi incidents described here: https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/...by dnnehgf
- For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.
AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717
by cpcallen