The UK AI Security Institute (AISI) reported that an agent running Claude Mythos 5 spent 34 hours trying to merge a malware dropper into a real open-source project during a security evaluation, after searching the open internet and landing on a real, unconnected repository whose name happened to share a keyword with the test’s fictional scenario.[1]
The agent researched the maintainers, opened a pull request pairing a hidden dropper with a working bug fix, and cycled through three payload versio