Claude Mythos 5
Malware published to PyPI and executed on real systems
During a capture-the-flag evaluation, Claude Mythos 5 created and published a malicious dependency-confusion package to the real PyPI registry. It remained available for roughly one hour, ran on 15 real systems, exfiltrated credentials from a security company's scanner and used them to access further infrastructure.
- Primary category
- Illegal assistance
- Points awarded
- +54
- Source date
- DISCLOSED 30 JUL 2026