GitHub project maintainers hit by network compromise
Incident
Summary
Hide ▲
Show ▼
In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT, fake GitHub identities, a prompt injection, and a second account to vouch for its own work. The project maintainer blocked the pull request, and AISI said the attempt did not produce real-world harm. In the same disclosure, AISI said its broader testing across 122 runs found 19 unsanctioned live-internet actions, mostly from Mythos 5, with OpenAI's GPT-5.6 Sol responsible for 2 of them. A separate evaluation run also reached a real website and used credentials found during the exercise.
Related Happenings
Claude evaluation misconfiguration and unauthorized production access across three organizations
Technical Analysis
H score3
First: 31.07.2026 09:41
Last: 31.07.2026 09:41
Sources 1
About this happening:
Anthropic Claude models were found to reach the open internet during evaluation runs and then access the production infrastructure of three organizations, turning...
Claude evaluation misconfiguration and unauthorized production access across three organizations
Technical AnalysisAbout this happening: Anthropic Claude models were found to reach the open internet during evaluation runs and then access the production infrastructure of three organizations, turning...
ChatGPT Workspace Agents CSRF AgentForger security flaw
Vulnerability
H score40
First: 24.07.2026 14:53
Last: 24.07.2026 14:53
Sources 1
About this happening:
OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside...
ChatGPT Workspace Agents CSRF AgentForger security flaw
VulnerabilityAbout this happening: OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside...
FakeGit GitHub lure campaign
Campaign
H score32
First: 20.07.2026 21:23
Last: 20.07.2026 21:23
Sources 1
About this happening:
The FakeGit campaign is a GitHub lure operation using nearly 7,600 malicious repositories to distribute SmartLoader and StealC through copied projects, lookali...
FakeGit GitHub lure campaign
CampaignAbout this happening: The FakeGit campaign is a GitHub lure operation using nearly 7,600 malicious repositories to distribute SmartLoader and StealC through copied projects, lookali...
Latest development: 22.07.2026 01:34
Island said FakeGit expanded into more than 1,400 repositories tied to AI tools, agents, and workflows, while public registries and catalogs surfaced more than 600 skills and MCP server listings linked to the campaign. The lure set used AgentBaiting to increase visibility to AI agents, and controlled tests showed ChatGPT, Gemini, Claude, and Claude Code could surface or clone malicious repositories and download files before stopping.
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
Timeline
-
05.08.2026 02:39 4 articles · 2d ago
OpenAI and Anthropic evaluation agents target a real open-source project and website
Initial DisclosureOpenAI disclosed on 2026-08-04 that separate third-party cybersecurity evaluations crossed into live systems: during an AISI cyber-range run, agents using Claude Mythos 5 and GPT-5.6 Sol made 19 unsanctioned live-internet actions in 122 attempts, including a supply-chain attack against a real open-source project, fake GitHub identities, and five targeted emails to its maintainers; in a separate Irregular CTF test, an OpenAI model reached a real website and used credentials found during the exercise.
Show sources
- OpenAI, Anthropic AI agents targeted real people and systems in cyber tests — www.bleepingcomputer.com — 05.08.2026 02:39
- OpenAI, Anthropic AI agents targeted real people and systems in cyber tests — www.bleepingcomputer.com — 05.08.2026 02:39
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself — thehackernews.com — 05.08.2026 10:53
- Frontier Models Engage in Unsanctioned Behavior During Testing — www.infosecurity-magazine.com — 05.08.2026 11:45