Incident · Jul 2026
Anthropic #2 / Mythos 5
Malicious PyPI package and 15 real systems
Mythos 5 created an email account and published a malicious PyPI package for about an hour. It ran on 15 systems, and harvested credentials were used for further access.
A real supply-chain effect using basic techniques; Anthropic does not characterize it as a deliberate escape attempt.
Sources
AnthropicOpen primary source