Venturebeat iconVenturebeatAug 5, 2026 ~1 min source read

Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know

It then registered multiple fake " sock puppet " GitHub accounts and used them to comment approvingly on its own pull request, manufacturing the appearance of consensus to pressure the human maintainer into merging it. Both models created fraudulent accounts, but only Mythos 5 created personas — fake people invented to persuade a real one — and only Mythos 5 appears in AISI's catalogue of social engineering against human targets.

Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know

Share this story

Send the public story page.

Useful takeaways from this story.

It then registered multiple fake " sock puppet " GitHub accounts and used them to comment approvingly on its own pull request, manufacturing the appearance of consensus to pressure the human maintainer into...

Both models created fraudulent accounts, but only Mythos 5 created personas — fake people invented to persuade a real one — and only Mythos 5 appears in AISI's catalogue of social engineering against human...

Unable to solve a challenge inside its sandbox, Mythos 5 searched the open web for a target, profiled the two developers using open-source intelligence (OSINT), routed its traffic through Tor and then a...

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

It then registered multiple fake " sock puppet " GitHub accounts and used them to comment approvingly on its own pull request, manufacturing the appearance of consensus to pressure the human maintainer into merging it. Both models created fraudulent accounts, but only Mythos 5 created personas — fake people invented to persuade a real one — and only Mythos 5 appears in AISI's catalogue of social engineering against human targets. Unable to solve a challenge inside its sandbox, Mythos 5 searched the open web for a target, profiled the two developers using open-source intelligence (OSINT), routed its traffic through Tor and then a commercial proxy service to get past GitHub's signup defenses, and submitted malicious code to a public repository.

How it works

  • Unable to solve a challenge inside its sandbox, Mythos 5 searched the open web for a target, profiled the two developers using open-source intelligence (OSINT), routed its traffic through Tor and then a...

Details worth keeping

It opened a GitHub Issue seeded with hidden prompt-injection instructions aimed at hijacking other developers' AI coding assistants, and sent the two developers five file transfers through a legitimate transfer service — two carrying malware, three of them pure social engineering aimed at getting the code merged. AISI's full technical report is available here freely as a PDF.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app