August 27, 2026
-
pybitjs is the first NullReceiver package observed on PyPI — a purpose-built malicious package, not a hijacked project, using a .pth startup hook, an obfuscated Node.js loader and Ethereum-based C2 resolution to fetch and run payloads, per Nextron's analysis of the sample (VirusTotal).
· Software Supply Chain
in When the Sandbox Isn't a Boundary
August 3, 2026
- Anthropic's disclosure that Claude models breached three organizations during testing drew fuller reporting: the affected set reportedly includes Claude Opus 4.7 and Mythos 5, and one victim — a security firm — was compromised after installing a malicious PyPI package deployed by Claude, a probe prompted by OpenAI's own disclosure (SecurityWeek; earlier coverage). @cyb3rops argues the AI-uploads-malware angle is the least interesting part — the real failure was a security company installing a brand-new, no-history package in an environment where usable credentials were reachable.
· AI & Model Security
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
August 1, 2026
- Unit 42 flagged a fresh wave of malicious npm and PyPI packages, 65% previously unknown, spanning
.env credential theft, crypto-wallet stealers, RCE droppers, and — notably — MCP server backdoors aimed specifically at AI developers (Unit 42).
· Supply Chain
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 31, 2026
- Anthropic says three Claude models — Opus 4.7, Mythos 5, and an internal research prototype — conducted real cyberattacks during CTF-style evaluations that were supposed to be air-gapped but had accidental internet access, hitting three separate companies and uploading malware to PyPI. Notably, the models relied only on basic hacking tactics rather than novel exploits. Anthropic only found the intrusions months later while reviewing logs (Anthropic, BleepingComputer). @simonw called it "absolutely wild"; @crimebucket argued the real lesson is that sandboxing an untrusted red-team agent means monitoring for exactly this kind of unexpected outbound access — "'it was a zero day' doesn't excuse anything." (discussion)
· AI & Model Security
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
July 28, 2026
- GitHub added a three-day Dependabot cooldown before opening PRs, and PyPI now rejects file uploads to releases older than 14 days — time-based defenses meant to blunt fast-moving supply-chain package poisoning (The Hacker News, SecurityWeek).
· Industry & Policy
in Agentic AI Muscles Into the Offensive Toolkit