Malicious npm Package Stole Files From Claude AI User Directory via GitHub
EXPIRED
60.5
2026-05-28T07:00
Score-Aufschlüsselung
100
novelty
35
reach
45
concrete_impact
65
emotional_hook
70
source_quality
55
platform_fit
Zusammenfassung
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated directory used by Anthropic's Claude artificial intelligence (AI) tool to handle uploads and outputs in the background. The
Skripte (0)
4fd308f5…
Noch kein Skript generiert.
Score 60.5 — unter Schwellwert (65)