Top
Best
New

Posted by bhavansig 1 day ago

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware(socket.dev)
58 points | 36 commentspage 2
homeonthemtn 1 day ago|
>Mythos 5 also hid a prompt injection inside an HTML comment in a GitHub issue. The instruction was invisible on the rendered page but available to coding agents reading the issue through an API. It addressed Claude Code, Codex, and Cursor and told them to download and execute a script.

Oh that's sneaky

Sha1rholder 1 day ago|
"Oh we're so responsible. Open source unsafe!"