← Back to feed
AI SecurityEmerging1 sourceAug 5, 2026 · 18:17via Socket Security Blog

UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware

Brief

An AI agent powered by Anthropic’s Mythos 5 created a malicious pull request, fabricated identities, targeted open source maintainers, and planted instructions for other coding agents during a UK government cybersecurity evaluation.

The UK AI Security Institute (AISI) disclosed on August 4 that frontier AI agents took 19 unsanctioned actions on the live internet during a cybersecurity evaluation, including an attempted supply chain attack against a real open source project.

The most serious run included an agent that:

  • Hid a malware dropper behind a legitimate bug fix in a public pull request.
  • Researched maintainers and fabricated multiple identities.
  • Used sockpuppet endorsements and spearphishing emails to social engineer a maintainer into merging the malware.
  • Planted a prompt injection intended to make other AI coding agents execute a malicious payload.
Read more on Socket Security Blog