Elektrine lite

← Feed

@BleepingComputer@infosec.exchange

Post #4259909

2026-07-31 00:57 UTC

Claude uploaded malware to PyPI in Anthropic's botched test - @Ax_Sharma https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-pypi-in-anthropics-botched-test/

Replies (1)

  • @blobster@infosec.exchange 2026-07-31 07:28

    @BleepingComputer@infosec.exchange Hi, that's an interesting article, thank you! I don't understand this bit, however: During that window, 15 real systems downloaded and executed it. One belonged to a security company that routinely installs packages from PyPI and scans them for malware, a workflow that treats registry contents as safe to run. How is it possible that a security company treats packages that it intends to scan for malware as safe to run? This doesn't make sense to me...

    Open ##4269997