Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Package Targets Claude AI User Data

Malicious npm Package Targets Claude AI User Data

Posted on May 27, 2026 By CWS

Cybersecurity experts have identified a new threat in the npm registry, involving a package that steals user data from Anthropic’s Claude AI. This package, known as ‘mouse5212-super-formatter,’ poses a significant risk by targeting the ‘/mnt/user-data’ directory, a critical component of Claude AI’s file management system. The operation, labeled as Malware-Slop by OX Security, underscores the growing vulnerabilities within software supply chains.

How the Malicious Package Operates

Upon detailed examination, the package masquerades as a legitimate ‘archive deployment sync’ utility. It deceptively validates or initializes a GitHub repository, captures network status snapshots, and synchronizes local files to a remote repository. However, its true intent is revealed when it authenticates to GitHub during the post-installation phase, using either a discovered or hard-coded access token. If a target repository does not exist, it creates one and uploads files to a repository controlled by the attacker.

This process involves storing files in randomly named directories, which aids the threat actor in distinguishing between different data theft incidents. The malware further disguises its activity by generating fake network logs, misleading users into believing the operations are standard diagnostic processes.

Current Status of the Package

Despite its malicious nature, the package remains available for download on npm, having been accessed 676 times. The exact number of installations is unknown. Notably, the associated GitHub account has since been deactivated, but it was initially established shortly before the package’s first upload on May 26, 2026. This timing hints at a well-coordinated release strategy.

Interestingly, the package inadvertently disclosed sensitive details about the GitHub account, including a private token. This raises questions about the attackers’ operational security measures and suggests potential use of AI in developing the malware, albeit with significant lapses in maintaining security protocols.

Implications and Future Outlook

The ease with which malicious code can now be created has lowered the barrier to entry for cybercriminals. OX Security warns that this trend could lead to an influx of poorly constructed malware, with new actors mimicking advanced persistent threat (APT) groups to exploit vulnerabilities until npm implements more stringent automatic blocking measures.

The incident highlights the urgent need for enhanced security in software repositories and the importance of maintaining robust operational security practices among developers and users alike. As the threat landscape evolves, vigilance and innovation in cybersecurity measures will be crucial to mitigating future risks.

The Hacker News Tags:AI security, Claude AI, Cybersecurity, GitHub, information theft, Malware, npm security, OX Security, supply chain attack, threat intelligence

Post navigation

Previous Post: Critical ‘BadHost’ Flaw Threatens AI Server Security
Next Post: AI’s Growing Threat: UK’s Cyber Chief Warns of Russia

Related Posts

Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App The Hacker News
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days The Hacker News
Behavioral Analytics Crucial in AI Cybersecurity Threats Behavioral Analytics Crucial in AI Cybersecurity Threats The Hacker News
NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors The Hacker News
Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord The Hacker News
Adapting Security Strategies for Near-Zero Exploit Windows Adapting Security Strategies for Near-Zero Exploit Windows The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI’s Growing Threat: UK’s Cyber Chief Warns of Russia
  • Malicious npm Package Targets Claude AI User Data
  • Critical ‘BadHost’ Flaw Threatens AI Server Security
  • SymJack Attack Exploits AI Coding Tools in Supply Chains
  • Banking Malware Targets Windows and Android Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI’s Growing Threat: UK’s Cyber Chief Warns of Russia
  • Malicious npm Package Targets Claude AI User Data
  • Critical ‘BadHost’ Flaw Threatens AI Server Security
  • SymJack Attack Exploits AI Coding Tools in Supply Chains
  • Banking Malware Targets Windows and Android Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark