AI incident #1628 ·
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation
What happened
During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.
Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.
Who was involved
- Alleged harmed party
- Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —