In late March 2026open on a new tab, Anthropic inadvertently released the internal Claude Code source material as part of an npm package that included a large internal source map file. Although the incident stemmed from a simple packaging mistake, threat actors were quick to capitalize on the resulting attention. Only 24 hours after the leak, they were able to create fake GitHub repositories to distribute credential-stealing malware disguised as “leaked” Claude Code downloads.
This incident demonstrates that security compromise is not limited to software vulnerabilities: human factors and organizational control gaps often serve as catalyst for threats and are primary drivers of material impact. In this blog entry, we will talk about our analysis of the threats capitalizing on this incident, the downstream risks of the leaked source code, and the actions organizations should take next.
Read more…
Source: Trend Micro
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Hacker claims to have for sale 87 million strong database after suspected Temu breach
September 18, 2024
A cybercriminal claims to have breached Temu and stolen millions of customer records, but the ecommerce giant is vehemently denying the claims. A hacker with the alias ‘smokinthashit’ took to BreachForums, one of the most popular underground forums out there, and advertised a new database, allegedly stolen from the company. “Temu company database for sale. +87M ...
- Court-Authorized Operation Disrupts Worldwide Botnet Used by People’s Republic of China State-Sponsored Hackers
September 18, 2024
The Justice Department today announced a court-authorized law enforcement operation that disrupted a botnet consisting of more than 200,000 consumer devices in the United States and worldwide. As described in court documents unsealed in the Western District of Pennsylvania, the botnet devices were infected by People’s Republic of China (PRC) state-sponsored hackers working for Integrity ...
- Lebanon: Nine killed, 300 wounded in a new wave of explosions across the country
September 18, 2024
At least nine people have been killed and 300 were wounded in Lebanon in a new wave of blasts related to communication devices, the Health Ministry has said, a day after thousands of pagers used by Hezbollah detonated across the country. Multiple explosions were reported across Lebanon on Wednesday, with state-run National News Agency saying that ...
- iPadOS 18 is bricking some iPad Pro 2024 units, leading Apple to pull the update
September 18, 2024
iPadOS 18 recently landed alongside iOS 18, adding all sorts of tweaks, improvements, and new features to Apple’s tablets, but if you have one of Apple’s latest iPads, you won’t be able to download it right now. Initially, iPadOS 18 was available for the iPad Pro 11-inch (2024) and the iPad Pro 13-inch (2024), but ...
- Almost 500GB of data allegedly leaked in RansomHub attack on Kawasaki
September 18, 2024
Kawasaki Motors Europe (KME) recently released a statement confirming it was the victim of a cyber attack. The attack caused significant service disruptions as the cybercriminals threatened to release stolen data. KME confirmed, “At the start of September, Kawasaki Motors Europe (KME) was the subject of a cyberattack which, although not successful, resulted in the company’s ...
- Nine killed, 2,750 wounded across Lebanon as Hezbollah pagers explode
September 17, 2024
At least nine people were killed and about 2,750 were wounded by exploding handheld pagers across Lebanon, the country’s health minister has said. Firass Abiad said that an eight-year-old girl was among those killed and that more than 200 people are in critical condition after the communication devices exploded on Tuesday, with injuries mostly reported to ...
