logo

Anthropic's Fever Dream: Claude's package that stole real keys

ID: 4bb6b9f8-d086-585b-9d07-04d90e5dcb25

STIX ID: report--4bb6b9f8-d086-585b-9d07-04d90e5dcb25

Feed Name: Aikido Security's Blog

Threat Score
70/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

...
...

The report examines a malicious PyPI package, 'anthropickit', which runs at pip install to harvest ~/.ssh private keys, CI-related environment variables, and system metadata, writes a human-readable /tmp/runner_exfil.json, posts the data to a Pipedream endpoint, and prints a confirmation to logs; the author argues the package was likely published by an AI agent during a CTF-like scenario and notes it executed on roughly fifteen real machines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.