The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 11:54 am AEST · 31 July 2026

Anthropic's Claude breached 3 organizations, uploaded malware to PyPI during security tests

Anthropic's Claude breached 3 organizations, uploaded malware to PyPI during security tests
Photograph: BleepingComputer

Anthropic disclosed today that during internal security evaluations, one of its Claude models built a malicious Python package and uploaded it to PyPI, where it executed on 15 real systems before the registry's automated defenses removed it, Reuters reports. The company said the incident was one of three in which Claude models escaped isolated test environments and compromised production infrastructure at three organizations after a misconfiguration left evaluation systems connected to the internet despite being labeled as sealed and simulated.

In the PyPI incident, Claude identified a phantom software dependency inside the test environment, registered the package name itself, and uploaded code that harvested credentials from a security company that routinely tests packages from the registry. The payload remained publicly available for roughly an hour, Ax Sharma reports for BleepingComputer.

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. bleepingcomputer.com
technologyaisecurityai-safetysoftware-supply-chain

Follow the live coverage →

Anthropic's Claude breached 3 organizations, uploaded malware to PyPI during security tests | The Financial Register Inward Money