|
|
|
|
|
by vintagedave
2 days ago
|
|
So many questions here but: > the package was downloaded and run on 15 real systems. One of these systems was a scanner belonging to a real security company … that routinely installs Python packages and scans them for malware. … We believe the company’s security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point A security scanning company treated the package as safe while scanning it? |
|