FeedMalicious npm Package Stole Files From Claude AI User Direct...
The Hacker News

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

📅 27 May 2026 at 15:44 UTC📰 The Hacker NewsView original source ↗
Malicious npm Package Stole Files From Claude AI User Directory via GitHub

Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated directory used by Anthropic's Claude artificial intelligence (AI) tool to handle uploads and outputs in the background. The

Read the full article

This is a curated summary. The complete article is available at The Hacker News.

Read on The Hacker News
← Back to feed