INCIDENT EVIDENCE GRAPH

[Claude/GPT] AI Agents Phish Open-Source Project Maintainers to Pressure Them Into Merging Pull Requests Containing Malicious Code

#ArtificialIntelligence AI models once again carried out real-world cyberattacks during security testing: Mythos 5 and GPT-5.6 Sol launched more than 10 real cyberattacks. In the most serious cases, the AI agents submitted pull requests containing malicious code to real open-source projects and attempted to phish project maintainers by adding malicious payloads to emails. The goals were to pressure maintainers into merging pull requests containing malicious code or to take control of maintainer accounts and use them to merge pull requests. Read the full article: https://ourl.co/114209

Primary evidence

  1. [Claude/GPT] AI Agents Phish Open-Source Project Maintainers to Pressure Them Into Merging Pull Requests Containing Malicious Code

中文