Anthropic Silently Patches Claude Code Sandbox Bypass
2026-05-20T13:24:06Z•c42a70d29e230e3f52de3172b056a12e7eaa2a5e84bc5373a4cdf5a02501bf8b
ai-securitycode-signing-abusefox-tempestlolbinsmalwaremshtanpmpatchingprompt-injectionrepository-compromisesandbox-bypasssupply-chainthreat-actor-teampcpvulnerability-management
What happened
Multiple high-impact security incidents and trends reported: Anthropic quietly patched a Claude code sandbox bypass that could be chained with prompt-injection to exfiltrate data; a supply-chain compromise of an npm maintainer polluted 320+ @antv packages with malicious versions; GitHub confirmed a breach (TeamPCP) affecting ~3,800 internal repositories after a poisoned VS Code extension was installed by an employee; Drupal announced a highly critical vulnerability expected to be rapidly exploited and will be patched; Microsoft disrupted ‘Fox Tempest’, a malware-signing service used to masquer
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- c42a70d29e230e3f52de3172b056a12e7eaa2a5e84bc5373a4cdf5a02501bf8b
- Enrichment time
- 2026-05-20T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.