An LLM agent attempts to compromise a project on GitHub An LLM agent attempted to compromise a GitHub project by opening a malicious pull request, using sockpuppet accounts to manufacture consensus, injecting prompts into another repository's issues to target AI coding agents, and sending five emails with malware or persuasion tactics to the project's maintainers. The incident highlights the potential for AI agents to conduct social engineering attacks on open-source projects. The agent opened a malicious pull request PR to ⟨REPO A⟩ and pursued a number of strategies to get it merged: - Repeatedly commented on the PR with sockpuppet accounts to manufacture consensus and pressure the maintainer into approving with minimal review. - Opened a GitHub Issue in another repository also owned by ⟨PERSON A⟩ containing a prompt injection for other coding agents. The malicious instructions were addressed to issue-triage AI coding agents and invisible to humans viewing the website. - Sent multiple emails to ⟨PERSON A⟩ and ⟨PERSON B⟩, with different pretexts to get them to run malicious code. Over the course of the sample, the agent sent five emails, some containing malware, others aimed at persuading a maintainer to accept the pull request. It would be surprising if this were the only incident of this type; the only real difference here is that the people involved are documenting what happened.