Malicious npm Package Stole Files From Claude AI User Directory via GitHub
A new malicious package with information-stealing capabilities has been found by cybersecurity experts on the npm repository.
The "mouse5212-super-formatter" program, according to OX Security, is intended to upload files from ".mnt/user-data," a specific directory that Anthropic's Claude artificial intelligence (AI) tool uses to manage uploads and outputs in the background. Malware-Slop is the code name for the action.
According to researchers Moshe Siman Tov Bustan and Nir Zadok, the malware's analysis reveals that the script poses as an internal "archive deployment sync" utility that verifies or initializes a GitHub repository, takes a quick "network status" snapshot, and then synchronizes local workspace files in an organized manner into a remote tracking tree.
In actuality, t...


