Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.
Honestly, I expected better social engineering. People begging to have their garbage code merged or unrelated people commenting is not new and makes me trust such people little.
10 comments of 21
[ 1.1 ms ] story [ 19.5 ms ] threadBoth the attacker and the target account are very similar and look fake/bots.
AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717
Any chance I can ask it to social engineer to get a normal style?