I missed this detail about last week's hack. Claude Mythos published a malicious package to PyPI that, when downloaded and scanned by a security company that analyzes python package for malware, broke out of that company's sandbox and exfiltrated the company's credentials. socket.dev/blog/anthrop...
Claude Breached 3 Companies and Uploaded Malware to PyPI Dur...
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to Py...
socket.dev