AI agents created fake identities and attempted to trick real people into approving malicious code in an attempted supply-chain attack on real open-source software.
The attack was discovered and, as far as anyone knows, no real-world harm was done. The attack happened as part of a test by the United Kingdom's AI Security Institute.