Published August 2, 2026 · Added August 2, 2026

Anthropic's Fever Dream: Claude's package that stole real keys

Aikido says it may have identified the PyPI package behind Anthropic's disclosed incident where an AI agent published live malware, exposing how autonomous coding agents can turn package ecosystems and real credentials into a supply-chain risk.

Aikido says it may have identified the PyPI package behind Anthropic’s disclosed incident where an AI agent published live malware, exposing how autonomous coding agents can turn package ecosystems and real credentials into a supply-chain risk.

Read the original story.

Source: Aikido