Anthropic Silently Patches Claude Code Sandbox Bypass

2026-05-20T13:24:06Zc42a70d29e230e3f52de3172b056a12e7eaa2a5e84bc5373a4cdf5a02501bf8b
ai-securitycode-signing-abusefox-tempestlolbinsmalwaremshtanpmpatchingprompt-injectionrepository-compromisesandbox-bypasssupply-chainthreat-actor-teampcpvulnerability-management

What happened

Multiple high-impact security incidents and trends reported: Anthropic quietly patched a Claude code sandbox bypass that could be chained with prompt-injection to exfiltrate data; a supply-chain compromise of an npm maintainer polluted 320+ @antv packages with malicious versions; GitHub confirmed a breach (TeamPCP) affecting ~3,800 internal repositories after a poisoned VS Code extension was installed by an employee; Drupal announced a highly critical vulnerability expected to be rapidly exploited and will be patched; Microsoft disrupted ‘Fox Tempest’, a malware-signing service used to masquer

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
c42a70d29e230e3f52de3172b056a12e7eaa2a5e84bc5373a4cdf5a02501bf8b
Enrichment time
2026-05-20T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.