Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

Python Package Index (PyPI) ecosystem

Incidents implicated systems

Incident 16284 Report
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

2026-07-30

During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Irregular

Incidents involved as Deployer
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Anthropic

Incidents involved as both Developer and Deployer
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

AI evaluation organizations

Incidents involved as Deployer
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Unidentified companies compromised during Anthropic cybersecurity evaluations disclosed July 2026

Incidents Harmed By
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Companies

Incidents Harmed By
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Large language models

Incidents implicated systems
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Cybersecurity AI systems

Incidents implicated systems
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Claude Mythos 5

Incidents implicated systems
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

Claude

Incidents implicated systems
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More
Entity

AI agent systems

Incidents implicated systems
  • Incident 1628
    4 Reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • 3e68a9f