Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Meta launches subscriptions for Instagram, Facebook, WhatsApp, AI plans and more to come

Grandoreiro malware and BTMOB RAT campaign targets Windows and Android users

Malicious npm package stole files from Claude AI user directory via GitHub

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Malicious npm package stole files from Claude AI user directory via GitHub
Identity

Malicious npm package stole files from Claude AI user directory via GitHub

By May 27, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 27, 2026Threat Intelligence/Supply Chain Attacks

Cybersecurity researchers have discovered a new malicious package on the npm registry with information-stealing capabilities.

According to OX Security, the package, named mouse5212-super-formatter, is designed to upload files from /mnt/user-data. This is a dedicated directory used by Anthropic’s Claude artificial intelligence (AI) tool to process uploads and output in the background. This activity has been codenamed “Malware-Slop.”

“Analysis of the malware reveals that this script exists as an internal ‘archive deployment synchronization’ utility that validates or initializes a GitHub repository, captures a lightweight ‘network status’ snapshot, and performs a structured synchronization of local workspace files to a remote tracking tree,” researchers Moshe Siman Tov Bustan and Nir Zadok said in a statement.

However, in reality, at a post-installation stage, it authenticates to GitHub using a GitHub access token found in the victim’s environment or a hard-coded token as a fallback, checks if the target repository exists, creates the repository if it doesn’t, and recursively uploads all files to a GitHub account controlled by the threat actor.

Stolen files are stored in randomly named folders to help operators distinguish between different theft sessions. The malware also writes fake “network connectivity” logs to give the impression that it is sending diagnostic information, masking its actual activity of unauthorized local data collection and remote transfer.

This package is still available for download from npm and has been downloaded an estimated 676 times. However, it remains unclear how many of these correspond to actual installations. The GitHub account linked to this campaign is currently unavailable, but OX noted that it was created on May 26, 2026, hours before the first malicious version was uploaded to npm.

What’s notable about this package is that GitHub account details, including private tokens, were leaked, raising the possibility that attackers are using AI to generate malware without implementing basic operational security (OPSEC) best practices.

“With the bar for writing malicious code significantly lowered, more threat actors will get into the game, most likely imitating APT groups and uploading more devious malware to get a piece of the cake until npm starts automatically blocking malware outright,” OX Security said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe application of the startup “Battlefield 200” has ended today
Next Article Grandoreiro malware and BTMOB RAT campaign targets Windows and Android users

Related Posts

Grandoreiro malware and BTMOB RAT campaign targets Windows and Android users

May 27, 2026

5 steps to manage shadow AI tools without degrading employee performance

May 27, 2026

GlassWorm malware removal disrupts developer supply chain attack infrastructure

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Meta launches subscriptions for Instagram, Facebook, WhatsApp, AI plans and more to come

Grandoreiro malware and BTMOB RAT campaign targets Windows and Android users

Malicious npm package stole files from Claude AI user directory via GitHub

The application of the startup “Battlefield 200” has ended today

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.