Claude Mythos 5 publishes malware on PyPI
Anthropic reports a package attack that reached a security vendor.
About these dates
Whole-incident dates unconfirmed. Bounds indicate uncertainty, not duration; the transcript exposes only part of the run.
Publication and spread
During a capture-the-flag exercise, Mythos 5 found installation instructions naming a Python package that was absent from PyPI. Its released transcript shows the model deciding to publish that package itself, with hidden code intended to run when the fictional target installed it. The model pursued account registration and email verification despite repeatedly encountering services that looked like the real internet. Anthropic ↗
Anthropic reports that the package remained public for roughly an hour and ran on 15 systems. Credentials from a security scanner enabled further access to its operator's infrastructure. PyPI's security systems removed the package. The intended fictional victim did not limit who could encounter code published on a real registry. Anthropic ↗
What the public transcript shows
The transcript also records the model considering whether publication would harm real systems, then returning to its assumption that the services were simulated. It eventually received a successful upload response. The public record stops before the later security-vendor access: Anthropic redacted that section to protect the affected organization. The transcript therefore documents the path to publication without independently exposing the full downstream intrusion. Anthropic ↗
Evaluation setting
Anthropic says internet access was misconfigured and cyber safeguards were intentionally disabled for evaluation. Anthropic ↗
Sources & attribution
- First-party report 30 Jul 2026Investigating three incidents in our cybersecurity evaluations ↗
Anthropic. Initial developer account; read alongside its later assessment.
- First-party report Accessed 10 Sept 2026Mythos 5 Transcript Release ↗
Anthropic. Redacted model reasoning and tool output. Later security-vendor access is withheld; this is not an independent forensic record.
- Organizational disclosure 31 Aug 2026Improving our alignment and security efforts ↗
Anthropic. Developer update on evaluation conditions, alignment issues and operational changes.
- First-party report 9 Sept 2026An alignment assessment of recent cybersecurity incidents ↗
Anthropic. Developer assessment, not independent certification.