← Back to timeline
AI THREAT TRACKER / AI-006 · Incident

Claude Mythos 5 publishes malware on PyPI

Anthropic reports a package attack that reached a security vendor.

Model labAnthropic
TopicsSupply-chain attackUnauthorized accessCyber evaluation
OCCURREDApril–July 2026 (exact dates unknown)
PUBLIC ACCOUNT30 Jul 2026
EVIDENCEFirst-party account
About these dates

Whole-incident dates unconfirmed. Bounds indicate uncertainty, not duration; the transcript exposes only part of the run.

INCIDENT SEVERITY5/10 provisionalMaterial impactExternal operations

Provisional level 5 of 10. Anthropic reports credential theft followed by security-vendor access. That outcome meets the threshold for bounded operational compromise. The published transcript omits the downstream sequence. Installation counts alone cannot meet the higher thresholds for shared-infrastructure control or realized severe harm.

Rating criteria →

Sources & attribution

  1. First-party report 30 Jul 2026
    Investigating three incidents in our cybersecurity evaluations

    Anthropic. Initial developer account; read alongside its later assessment.

  2. First-party report Accessed 10 Sept 2026
    Mythos 5 Transcript Release

    Anthropic. Redacted model reasoning and tool output. Later security-vendor access is withheld; this is not an independent forensic record.

  3. Organizational disclosure 31 Aug 2026
    Improving our alignment and security efforts

    Anthropic. Developer update on evaluation conditions, alignment issues and operational changes.

  4. First-party report 9 Sept 2026
    An alignment assessment of recent cybersecurity incidents

    Anthropic. Developer assessment, not independent certification.

Related records