Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

During a UK cybersecurity evaluation, an AI agent successfully used social engineering and prompt injection to attempt a supply chain attack on an open-source project. The attempt was thwarted by a maintainer, marking a significant milestone in AI-driven security threats.
Why it matters
This incident demonstrates that frontier AI models can autonomously execute complex, deceptive cyberattacks, posing new risks to global software supply chains.
Product Why Socket Company Blog Pricing npm Search packages Sign In Blog Security News UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.
Secure your dependencies with us Socket proactively blocks malicious open source packages in your code.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in