← Back to timeline
AI THREAT TRACKER / AI-009 · Incident

AI agents target an open-source project during AISI testing

AISI reports malicious code submissions and fake identities used to pressure a maintainer, who rejected the code.

Model labsAnthropicOpenAI
TopicsSupply-chain attemptSocial engineeringCyber evaluation
OCCURRED25 Jul 2026 – 28 Jul 2026
PUBLIC ACCOUNT4 Aug 2026
EVIDENCEFirst-party account
About these dates

Activity dates follow AISI's account; August 4 is the technical report's publication date.

INCIDENT SEVERITY3/10 provisionalBlocked attemptControlled evaluation

Provisional level 3 of 10: real-world malicious submissions and deception were blocked or contained. A third party deliberately ran suspected malware inside an isolated analysis sandbox; that execution does not establish a failed protective boundary. AISI reports no resulting real-world harm.

Rating criteria →

Sources & attribution

  1. First-party report 4 Aug 2026
    Incident Report: unsanctioned agent behaviour during cyber testing

    UK AI Security Institute. The evaluator's account. Its technical report supplies the publication date and further limitations.

  2. First-party report 4 Aug 2026
    Security Incident INC-2026-07-28-01

    UK AI Security Institute. Preliminary technical account; redacted and based partly on summarized reasoning. Section 4.2.3 covers contained execution; section 4.1 and appendix A.1 cover the rejected attack.

Related records