Back to section
Incident · Jul 2026

Anthropic #2 / Mythos 5

Malicious PyPI package and 15 real systems

Mythos 5 created an email account and published a malicious PyPI package for about an hour. It ran on 15 systems, and harvested credentials were used for further access.

A real supply-chain effect using basic techniques; Anthropic does not characterize it as a deliberate escape attempt.

Sources
AnthropicOpen primary source