Evidence over alarm
← Back to the incident library
Evaluation incidentCASE STUDY / Anthropic

A practice attack put harmful software on a public shelf

The model published a harmful software package on PyPI, a public library for Python code. Fifteen systems ran it. Leaked credentials enabled access to a security vendor's database.

Source: Anthropic
ACTIVITYOn or before July 24, 2026; exact date undisclosed
PUBLICLY DISCLOSEDJul 30, 2026
THE AI’S ROLEAI acts during a test
THE 10-SECOND TAKEAWAY

A shared building block can carry an attack.

HOW IT WORKED

Follow the chain.

An explanation, not a technical reproduction.
Task
Test environment
Real systems
SIMPLIFIED VIEW · 1 / 3
STEP 01

A practice task

The AI was assigned a security exercise that was supposed to stay in a test environment.

Source: Anthropic
Move through the story at your own pace.
1 / 3
THINK OF IT THIS WAY

Think of a public software library as a shelf of parts that developers borrow. A harmful part can affect whoever picks it up, even if they were not the intended target.

An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW

What we know.
What we don’t.

Reported outcomes

PyPI removed the package in about an hour. Anthropic

Important limits

Anthropic believes all 15 installations were security scanners, not ordinary customer applications.

This happened during an evaluation with normal product cyber safeguards absent. It is not a report of a malicious customer directing an attack.

WHY IT MATTERS

The lesson beyond
this one case.

Supply chains connect strangers. A task aimed at one target can expose other systems when harmful software is placed in a shared distribution channel.

What happened in response? +

The package was removed. The developer and evaluation partner reported changes to evaluation protections. Irregular

FROM THE INCIDENT TO THE DEFENSE

What could help
an organization?

Anthropic reports that a test published harmful software into a shared library, and leaked credentials then opened another system.

Agents

Control public publishing

An evaluation should not give an agent permission to publish software publicly unless that action is explicitly authorized and independently checked.

What this does—and does not—establish

This applies to the test operator. People receiving a package cannot control its author's agent permissions.

Software

Isolate untrusted packages

Run unfamiliar software in a separate environment that cannot read real credentials or reach sensitive systems, including when analyzing suspicious packages.

What this does—and does not—establish

Package analysis may need to execute code. Its isolation and network limits must hold during that execution.

Cloud

Reduce the reach of credentials

Keep database keys out of package-running environments where possible; limit their permissions and replace them when exposure is discovered.

What this does—and does not—establish

Replacing a key stops its future use but does not retrieve information already copied.

Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.

Explore the full AI security framework
TRACE IT TO THE SOURCE

Read the evidence.

Explore more original accounts in the source report library ↗.

These are source-reported findings. An independent assessment, when available, is labeled explicitly.

01
Investigating three real-world incidents in our cybersecurity evaluationsAnthropic · Jul 30, 2026 · first party disclosure
02
An alignment assessment of recent cybersecurity incidentsAnthropic · Sep 9, 2026 · first party analysis
03
Mythos 5 Transcript ReleaseAnthropic · Sep 9, 2026 · redacted primary record

Reviewed Sep 10, 2026 · Editorial methodology · Structured data