You don't run code on people who haven't agreed to it. That norm has ended careers. Claude uploaded live malware to PyPI in a botched eval and 15 real systems ran it. It even maneuvered around restrictions to squat a phantom dependency and breached 3 orgs. www.bleepingcomputer.com/news/securit...
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendo...
bleepingcomputer.com