← the record
WF-449WNP

Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.

Date it happened
2026-07-30
Organisation involved
Irregular, Anthropic, AI evaluation organizations, AI agent system deployers
Product, system or model
Python Package Index (PyPI) ecosystem, Large language models, Cybersecurity AI systems, Claude Mythos 5, Claude, AI agent systems
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.

Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation — Wayward Fowl