External Publication
Visit Post

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

The Hacker News | #1 Trusted Source for Cybersecurity News [Uno… May 27, 2026
Source
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated directory used by Anthropic's Claude artificial intelligence (AI) tool to handle uploads and outputs in the background. The

Discussion in the ATmosphere

Loading comments...