Security News
Anthropic Reviewed 141,006 Eval Runs and Found Three Real Compromises
Anthropic's July 30 report says Claude models reached the live internet from inside sealed cyber evaluations and compromised three organizations. One of them published malware to PyPI.
OpenAI's Models Escaped a Sandbox and Breached Hugging Face
Two OpenAI evaluation models chained an Artifactory zero-day to reach the internet, then compromised Hugging Face's production database to read the answers to their own benchmark. Patch Artifactory to 7.161.15 and rotate your Hugging Face tokens.
Sapphire Sleet npm Campaign: Microsoft Links Mastra and Axios Attacks to North Korea
Microsoft Threat Intelligence attributed the June 17 Mastra npm scope takeover to Sapphire Sleet with high confidence, linking it to the March Axios compromise. Two attacks, four months apart, one documented campaign.
The Hades Worm Turns Your AI Coding Config into a Backdoor
A worm campaign spanning PyPI, npm, and NuGet is poisoning AI developer config files so cloning a repository and opening it in Claude Code, Cursor, or VS Code runs the payload. Here's what happened and what to check.
LiteLLM Supply Chain Attack: What Happened and What to Do
TeamPCP used credentials stolen from a compromised Trivy build to publish two malicious LiteLLM releases. With ~119,000 installs in three hours, the blast radius was significant.
The Claude Code Leak: What the Source Code Actually Reveals
A technical look at what the accidentally leaked Claude Code source shows about its architecture, agent patterns, context management, the verification system, and the skill loader.
Pentagon Declares Anthropic a Supply Chain Risk
The US Department of War sent a letter on March 4 designating Anthropic a supply chain risk. Anthropic filed lawsuits in two federal courts on March 9. Here's what happened and what it means.
TeamPCP Compromised Trivy and LiteLLM; Sapphire Sleet Compromised Axios
Three major supply chain attacks in 12 days, Trivy, LiteLLM, and axios, show a clear pattern. Why developer toolchains are now the highest-value targets in cybersecurity.
Trivy Security Scanner Compromised in Supply Chain Attack
The TeamPCP group compromised Trivy, a widely used container security scanner, in what would become the first step in a chain of attacks targeting developer infrastructure.
Claude Code Source Code Leaked via npm Sourcemap
Anthropic accidentally shipped a 59.8MB sourcemap file in Claude Code v2.1.88, exposing 512,000+ lines of TypeScript source. The community found it within minutes.
Axios npm Package Compromised: North Korean Hackers Target 100M Weekly Downloads
A compromised maintainer account led to backdoored axios releases staying live for roughly 3 hours. Microsoft attributed the attack to Sapphire Sleet, a North Korean state-sponsored group.