Malicious npm package targets Claude AI users, leaks own GitHub token in sloppy attack

2 Sources

Share

A malicious npm package called mouse5212-super-formatter targeted users of Anthropic's Claude AI coding tool, stealing files from the /mnt/user-data directory before the attacker accidentally leaked their own GitHub private token. The AI-generated malware reached 676 downloads before removal, highlighting how threat actors are increasingly using AI to create sloppy malware with poor operational security.

Malicious npm Package Targets Claude AI Users

A malicious npm package named mouse5212-super-formatter has been discovered targeting users of Claude AI, Anthropic's AI coding tool, in what security researchers are calling a particularly sloppy cybersecurity incident

1

2

. The package, which reached 676 downloads before being removed from the registry, was designed for stealing user data from the /mnt/user-data directory—a dedicated storage location that Anthropic's AI coding tool uses to handle file uploads, downloads, and code outputs.

Source: Hacker News

Source: Hacker News

AI-Generated Malicious Code Exposes Attacker's Identity

What makes this incident particularly notable is that the attacker leaked their own GitHub private token while deploying the AI-generated malicious code, allowing OX Security researchers Moshe Siman Tov Bustan and Nir Zadok to trace the stolen files and analyze the malware's operations

1

. The GitHub account associated with the attack was created on May 26, 2026, just hours before the first malicious version was uploaded to npm, and was subsequently deleted after the attack was exposed

2

. This operational security failure demonstrates how threat actors using AI to generate malware may lack fundamental best practices in concealing their activities.

Source: The Register

Source: The Register

Stealing Files from Claude AI User Directory

The malicious package disguised itself as an internal "archive deployment sync" utility that appeared to validate GitHub repositories and synchronize workspace files . In reality, mouse5212-super-formatter authenticated to GitHub during the postinstall stage using either a victim's environment token or a hardcoded fallback, checked whether a target repository existed, created it if needed, and then recursively uploaded every file through the GitHub Contents API

1

. The stolen files were stored under randomly named folders to enable multiple stealing sessions, with sensitive information exfiltrated using base64 encoding.

Growing Threat of Sloppy Malware

The malware attempted to appear legitimate by writing a phony network connection log to make it look like a diagnostic tool rather than a theft mechanism, using "intentionally bland" technical comments and commit messages to reduce suspicion

1

. Security researchers warn that this incident represents a troubling trend: "Now that the bar to create malicious code was reduced significantly, we're going to see more threat actors getting into the game - uploading more sloppy malwares, mostly mimicking APT groups to get a slice of the cake until npm starts automatically blocking malware completely," according to OX Security .

Immediate Actions Required

All versions of mouse5212-super-formatter are affected by this data compromise

1

. Users who installed the package should immediately revoke their GitHub access tokens and assume any unusual files in the /mnt/user-data directory have been compromised. The incident underscores the evolving challenge facing package registries and developers as AI lowers the technical barrier for creating malicious code, even if the resulting attacks demonstrate poor operational security. Developers should remain vigilant about verifying package authenticity and monitoring for suspicious activity in their development environments, particularly when working with AI coding tools that maintain dedicated storage directories.

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved