An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute.When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html
![]()

