Mythos social engineering AISI INC-2026-07-28-01
28 points - today at 3:41 AM
Sourcesummarity
today at 4:23 AM
Working with maintainers (on the GitHub side) thereβs definitely been a rise of malware dropper attacks against popular OSS repos, though this is particularly brazen - pressure tactics and all.
Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
I saw a contribution by this maintainer to another user who ALSO HAS 14.5k followers: https://github.com/yumiaura/myCat/pull/99 "yumiaura" and a preference for "my[APPNAME]" repo naming.
What is this?
Are the histories that Github presents all derived from someone's uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the "github commit graph" will dutifully represent this claim in its green-colored activity graph?
They're almost certainly not genuine accounts, maybe used for phishing or social engineering?
What does this malware do? Who operates it?
Wait, who is the robot? Am I getting that right, someone in that thread is AI?
Iβ¦I think there are no humans in that thread. Maybe only sinan-can-demir.
I'm 99.9% sure that everyone is AI in that thread.
holy shit
Yeah, if this is the new normal I might start day drinking at some point in the coming weeks.