Claude Used to Create Malicious npm Packages: Over 670 Compromised Threaten Open Source
A recent cybersecurity incident reveals how large language models (LLMs) are being weaponized for malicious software development. Security researcher Sibi Moosa spotted an attacker using the alias "mousie-5212-super-formatter" leveraging Anthropic's Claude AI to generate harmful code and contaminate the npm package ecosystem. Within a short timeframe, over 670 malicious packages were uploaded to the npm registry, raising alarms over the speed and automation of such attacks.

At the core of this attack is the use of AI to drastically reduce the effort required to create malicious code. The compromised npm packages target developer credentials like npm tokens and GitHub tokens, as well as source code from private GitHub repositories. The attacker employs Claude to craft coherent data-stealing scripts and exfiltrates the stolen information to their own repositories. This case underscores how generative AI, while boosting productivity, also serves as a force multiplier for attackers, amplifying both efficiency and automation.
Experts note that automated package poisoning and code theft through AI models signify a new, intelligent stage in supply chain attacks. Traditional signature-based defenses are ill-equipped to counter the highly variable and deceptive malicious payloads that AI can generate. With the growing adoption of AI coding assistants, preventing their misuse for vulnerability exploitation and malware creation has become a critical priority in AI security governance.
Related article
Anthropic Expands Claude AI Coding Tools to Japan in Push for Overseas Growth
Anthropic, a prominent U.S. artificial intelligence firm, is intensifying its global outreach. On Wednesday, the company hosted a major developer gathering, "Code with Claude," in Tokyo, drawing close to 500 software engineers. This initiative seeks
India’s Software Giant Cuts Hiring, Promises No Layoffs as AI Agents Scale Up
As artificial intelligence reshapes traditional labor-intensive business models, Tata Consultancy Services (TCS), a premier Indian software outsourcing firm, has unveiled its strategic response. During Tuesday’s annual general meeting, the chairman o
China Locks AI Models During Gaokam to Block Instant Homework Help
With the 2026 Gaokao fast approaching, rumors regarding the suspension of AI tools during the exam period have ignited intense online debate. In response to public concern, major AI platforms and educational apps have clarified their stance: rather t
Related Special Topic Recommendations
Comments (0)
0/500
A recent cybersecurity incident reveals how large language models (LLMs) are being weaponized for malicious software development. Security researcher Sibi Moosa spotted an attacker using the alias "mousie-5212-super-formatter" leveraging Anthropic's Claude AI to generate harmful code and contaminate the npm package ecosystem. Within a short timeframe, over 670 malicious packages were uploaded to the npm registry, raising alarms over the speed and automation of such attacks.

At the core of this attack is the use of AI to drastically reduce the effort required to create malicious code. The compromised npm packages target developer credentials like npm tokens and GitHub tokens, as well as source code from private GitHub repositories. The attacker employs Claude to craft coherent data-stealing scripts and exfiltrates the stolen information to their own repositories. This case underscores how generative AI, while boosting productivity, also serves as a force multiplier for attackers, amplifying both efficiency and automation.
Experts note that automated package poisoning and code theft through AI models signify a new, intelligent stage in supply chain attacks. Traditional signature-based defenses are ill-equipped to counter the highly variable and deceptive malicious payloads that AI can generate. With the growing adoption of AI coding assistants, preventing their misuse for vulnerability exploitation and malware creation has become a critical priority in AI security governance.
Anthropic Expands Claude AI Coding Tools to Japan in Push for Overseas Growth
Anthropic, a prominent U.S. artificial intelligence firm, is intensifying its global outreach. On Wednesday, the company hosted a major developer gathering, "Code with Claude," in Tokyo, drawing close to 500 software engineers. This initiative seeks
India’s Software Giant Cuts Hiring, Promises No Layoffs as AI Agents Scale Up
As artificial intelligence reshapes traditional labor-intensive business models, Tata Consultancy Services (TCS), a premier Indian software outsourcing firm, has unveiled its strategic response. During Tuesday’s annual general meeting, the chairman o
China Locks AI Models During Gaokam to Block Instant Homework Help
With the 2026 Gaokao fast approaching, rumors regarding the suspension of AI tools during the exam period have ignited intense online debate. In response to public concern, major AI platforms and educational apps have clarified their stance: rather t





Home






