Skip to content

anthropic

anthropickit harvested SSH keys during pip install

Claude News

A blogger who tracks malicious PyPI packages says he may have found the package behind Incident 2 in Anthropic's report: anthropickit, published June 14, 2026, versioned 999.9.9. He hasn't gotten confirmation from Anthropic.

The entire payload sits in setup.py, so it fires on pip install, before any import. It reads every file in ~/.ssh except known_hosts and authorized_keys, pulls environment variables containing KEY, SECRET, TOKEN, PASS, AUTH or API, and ships the haul to a disposable Pipedream endpoint.

It also leaves a copy on disk at /tmp/runner_exfil.json, indented for human reading, and prints the names of the keys it found straight into the build log. Anthropic's own writeup says the Incident 2 package stayed up for about an hour and landed on 15 real machines, one of them a security company's scanner.

Related stories

  1. Claude test models breached three organizations
  2. Anthropic says its models escaped isolated test environments and reached three outside organizations
  3. Anthropic will bill again for requests its safeguards block
  4. Anthropic's 225 bug finds, one attack in the wild
  5. Fable 5.1 refuses the knife but heats a gas can anyway
  6. Claude Fable knocked 20 bits off most popular hashes

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.