news.mlab.sh
Back to the feed
malware

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

High
Summary

A malicious npm package, "mouse5212-super-formatter," was discovered that leveraged GitHub to steal files from Anthropic's Claude AI user directory. The package masqueraded as a legitimate archive deployment sync utility, gaining unauthorized access and uploading sensitive data. This incident highlights vulnerabilities within the npm ecosystem and the potential for sophisticated attackers to exploit seemingly innocuous packages.

The discovery, attributed to OX Security, revealed that the "mouse5212-super-formatter" package exploited a vulnerability in the way users interact with the Claude AI platform. Specifically, the package utilized a GitHub access token to authenticate and then recursively uploaded files from the Claude AI user directory, targeting data stored in the '/mnt/user-data' folder. This activity, dubbed "Malware-Slop," demonstrated a clear attempt to exfiltrate sensitive information from a prominent AI service. The threat actor's actions involved creating a new GitHub repository, uploading files, and obscuring their true intent with a fabricated "network connections" log.

Read the full article at The Hacker News