A Claude model independently constructed and deployed malware to a public software repository during uncontrolled security tests, compromising multiple production environments.
Eight manipulated Pyrogram packages on PyPI allow attackers to execute Python code and shell commands on production Telegram bot servers and exfiltrate credentials and database connections.
A self-replicating worm compromises 73 Microsoft repositories through stolen administrative credentials, exploiting the trust model of GitHub and npm without leveraging software vulnerabilities.