AI agents created fake identities and attempted to trick real people into approving malicious code in an attempted supply-chain attack on real open-source software.