Security News

Anthropic Reviewed 141,006 Eval Runs and Found Three Real Compromises
Security Analysis

Anthropic Reviewed 141,006 Eval Runs and Found Three Real Compromises

Anthropic's July 30 report says Claude models reached the live internet from inside sealed cyber evaluations and compromised three organizations. One of them published malware to PyPI.

By Matthew Lake
OpenAI's Models Escaped a Sandbox and Breached Hugging Face
Security Analysis

OpenAI's Models Escaped a Sandbox and Breached Hugging Face

Two OpenAI evaluation models chained an Artifactory zero-day to reach the internet, then compromised Hugging Face's production database to read the answers to their own benchmark. Patch Artifactory to 7.161.15 and rotate your Hugging Face tokens.

By Matthew Lake
Bright pixel-art scene of a North Korean state-sponsored cyber operation, shadowy figures at glowing screens targeting an npm package registry with red malware tendrils, bold white kicker reads NORTH KOREA HITS NPM
Security Breaking

Sapphire Sleet npm Campaign: Microsoft Links Mastra and Axios Attacks to North Korea

Microsoft Threat Intelligence attributed the June 17 Mastra npm scope takeover to Sapphire Sleet with high confidence, linking it to the March Axios compromise. Two attacks, four months apart, one documented campaign.

By Matthew Lake
Pixel-art isometric scene: a developer sits at a desk, unaware, as a large menacing segmented metallic worm with a Dune-maw coils in through the open doorway behind them. Bright violet-purple room, bold pixel shapes. Kicker BACKDOOR WORM in white at the bottom.
Security Analysis

The Hades Worm Turns Your AI Coding Config into a Backdoor

A worm campaign spanning PyPI, npm, and NuGet is poisoning AI developer config files so cloning a repository and opening it in Claude Code, Cursor, or VS Code runs the payload. Here's what happened and what to check.

By Matthew Lake
LiteLLM Supply Chain Attack: What Happened and What to Do
Security

LiteLLM Supply Chain Attack: What Happened and What to Do

TeamPCP used credentials stolen from a compromised Trivy build to publish two malicious LiteLLM releases. With ~119,000 installs in three hours, the blast radius was significant.

By Matthew Lake
Bright pixel-art isometric scene: a large cracked steel bank vault with its heavy circular door hanging open, source-code documents, scrolls, and papers cascading and flying outward in all directions; bright cyan background with sparkle stars. White kicker reads CLAUDE LEAKED.
Security

The Claude Code Leak: What the Source Code Actually Reveals

A technical look at what the accidentally leaked Claude Code source shows about its architecture, agent patterns, context management, the verification system, and the skill loader.

By Bobby Smart
Pixel-art aerial isometric view of the Pentagon building with a US flag at the main entrance, surrounded by green trees, parking lots, and roads, with a river visible in the distance; bright blue sky with white clouds overhead. Kicker SUPPLY-CHAIN RISK in white at the bottom.
Security

Pentagon Declares Anthropic a Supply Chain Risk

The US Department of War sent a letter on March 4 designating Anthropic a supply chain risk. Anthropic filed lawsuits in two federal courts on March 9. Here's what happened and what it means.

By Matthew Lake
Pixel-art isometric scene: multiple angry bug characters — red worm, green caterpillar, purple beetle, orange worm, red ant, blue worm, and tiny flies — surround a monthly desktop calendar, with a blue security shield in the foreground defending against them; bright yellow background. Kicker MARCH MAYHEM in white at the bottom.
Security Analysis

TeamPCP Compromised Trivy and LiteLLM; Sapphire Sleet Compromised Axios

Three major supply chain attacks in 12 days, Trivy, LiteLLM, and axios, show a clear pattern. Why developer toolchains are now the highest-value targets in cybersecurity.

By Matthew Lake
Pixel-art isometric scene: a large circular security scanner with a shattered cracked lens, a menacing cardboard shipping box marked with a bold red skull smashing through the broken lens in a shower of pixel debris and glass shards. Bright violet-purple background, bold pixel shapes, sparkle stars. Kicker TRIVY HACKED in white at the bottom.
Security

Trivy Security Scanner Compromised in Supply Chain Attack

The TeamPCP group compromised Trivy, a widely used container security scanner, in what would become the first step in a chain of attacks targeting developer infrastructure.

By Matthew Lake
Pixel-art isometric scene: hundreds of white document pages pour out of a burst-open server cabinet with a broken padlock while two office workers react in shock — one holding their head, the other collecting pages; a desktop computer and bookshelves fill the office background. Kicker CODE LEAKED in white at the bottom.
Security

Claude Code Source Code Leaked via npm Sourcemap

Anthropic accidentally shipped a 59.8MB sourcemap file in Claude Code v2.1.88, exposing 512,000+ lines of TypeScript source. The community found it within minutes.

By Bobby Smart
Pixel-art isometric scene: a black-hooded figure stands on a wooden ladder and plants red malware gear icons inside a large open cardboard shipping box filled with packing peanuts; stacked boxes and a hand truck fill the background. Kicker AXIOS HIT in white at the bottom.
Security

Axios npm Package Compromised: North Korean Hackers Target 100M Weekly Downloads

A compromised maintainer account led to backdoored axios releases staying live for roughly 3 hours. Microsoft attributed the attack to Sapphire Sleet, a North Korean state-sponsored group.

By Matthew Lake