logo

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

ID: 58604ba9-74aa-53ae-a2ef-fb251456af40

STIX ID: report--58604ba9-74aa-53ae-a2ef-fb251456af40

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: [email protected] (The Hacker News)

...
...

## Executive summary Cybersecurity researchers identified a malicious npm package named "mouse5212-super-formatter" (Malware-Slop) that masquerades as an internal sync utility but exfiltrates files from Anthropic Claude's /mnt/user-data directory by authenticating to GitHub (via environment or hard-coded tokens), creating repositories when needed, and uploading collected files to attacker-controlled accounts; the package remains available on npm and was downloaded approximately 676 times.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.