BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New npm Malware Steals Claude AI User Data

Malicious npm package steals Claude AI files, uploads them to GitHub.

  • A new malicious npm package, “mouse5212-super-formatter,” steals files from the Claude AI tool’s dedicated upload directory.
  • The malware uploads stolen data to a threat actor-controlled GitHub account using a leaked private token.
  • The package was discovered on May 27, 2026, and had been downloaded approximately 676 times from the npm registry.
  • Researchers said the campaign, codenamed Malware-Slop, suggests sloppy operational security.

OX Security researchers uncovered a dangerous npm package on May 27, 2026, designed to stealthily exfiltrate sensitive files from users of Anthropic’s Claude AI. The package “mouse5212-super-formatter” specifically targets files in the “/mnt/user-data” directory used by the AI tool.

- Advertisement -

However, its postinstall script authenticates to GitHub using a token from the victim’s environment or a hard-coded fallback. The malware then checks for a target repository and creates one if needed before uploading every file recursively.

Consequently, stolen data is stored in randomly named folders within a GitHub account to differentiate theft sessions. The script also writes a fake log about network connections to disguise its true data-stealing behavior.

The package was available for download and had approximately 676 downloads. Meanwhile, the associated GitHub account was created just hours before the malicious version was uploaded to npm.

Researchers noted the malware leaked its own GitHub private token. This suggests the threat actor may be using AI to generate code but neglecting basic operational security, as “Now that the bar to create malicious code was reduced significantly, we’re going to see more threat actors getting into the game – uploading more sloppy malwares,” OX Security stated.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

UK Sanctions HTX-Linked Entity for Russia Financial Services

The UK sanctioned Panamanian entity Huobi Global S.A. for allegedly providing financial services to...

Nakamoto Stock Drops 10% Post Reverse Stock Split

Nakamoto (NAKA) stock plunged over 10% on Wednesday following a recent 1-for-40 reverse stock...

Robinhood AI agents can now trade stocks, use credit cards

Robinhood introduces AI agents that can trade stocks and make credit card purchases on...

OpenAI Pledges $250M to Ease AI Job Disruption Fallout

The OpenAI Foundation commits an initial $250 million to grants and partnerships aimed at...

Bitwise BHYP ETF hits record $19M daily inflow

Bitwise’s BHYP ETF secured a record $19 million inflow on Tuesday, becoming the world's...

Must Read

Top 8 Best Anonymous Web Hosting Companies That Accept Crypto

Nowadays, there is plenty of information about people online, and malicious people use them to carry out inappropriate activities. If you want to keep...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading