BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New npm Malware Steals Claude AI User Data

Malicious npm package steals Claude AI files, uploads them to GitHub.

  • A new malicious npm package, “mouse5212-super-formatter,” steals files from the Claude AI tool’s dedicated upload directory.
  • The malware uploads stolen data to a threat actor-controlled GitHub account using a leaked private token.
  • The package was discovered on May 27, 2026, and had been downloaded approximately 676 times from the npm registry.
  • Researchers said the campaign, codenamed Malware-Slop, suggests sloppy operational security.

OX Security researchers uncovered a dangerous npm package on May 27, 2026, designed to stealthily exfiltrate sensitive files from users of Anthropic’s Claude AI. The package “mouse5212-super-formatter” specifically targets files in the “/mnt/user-data” directory used by the AI tool.

- Advertisement -

However, its postinstall script authenticates to GitHub using a token from the victim’s environment or a hard-coded fallback. The malware then checks for a target repository and creates one if needed before uploading every file recursively.

Consequently, stolen data is stored in randomly named folders within a GitHub account to differentiate theft sessions. The script also writes a fake log about network connections to disguise its true data-stealing behavior.

The package was available for download and had approximately 676 downloads. Meanwhile, the associated GitHub account was created just hours before the malicious version was uploaded to npm.

Researchers noted the malware leaked its own GitHub private token. This suggests the threat actor may be using AI to generate code but neglecting basic operational security, as “Now that the bar to create malicious code was reduced significantly, we’re going to see more threat actors getting into the game – uploading more sloppy malwares,” OX Security stated.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Audit Gap Exposed As AI Finds Major Four-Year Crypto Bug

A critical four-year-old bug in ZCash's shielded pool, discovered in June 2026, wiped out...

Z.ai’s GLM-5.2 Nears Claude Opus, Beats GPT-5.5, MIT Licensed

Z.ai released the GLM-5.2 AI model, which performs within 1% of Claude Opus 4.8...

Strategy loses 40 years of dividend coverage in 7 months

Strategy lost 40 years of forecasted dividend coverage in just seven months.The coverage decline...

HIVE to deploy GPUs for Cohere in $220M AI cloud deal

HIVE Digital Technologies has signed a major three-year GPU cloud contract with Bell AI...

Apple warns of price hikes due to soaring AI chip costs

Apple CEO Tim Cook confirmed unavoidable price increases for most products due to soaring...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading