AIPolicyTracker

AI incident ·

Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

15 news reports Snapshot 7 Sep 2026

In brief

An AI system built by Large Language Model Developers, Anthropic and 1 other and deployed by Irregular, Anthropic and 2 others allegedly harmed Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026 and Companies.

Risk domain
Not classified
Occurred
Coverage
15 reports

What happened

During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

Who was involved

Alleged harmed party
Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Other incidents involving Irregular, Anthropic, Ai Evaluation Organizations, Ai Agent System Deployers

Source record: incident #1628 on the AI Incident Database · all 15 reports