Anthropic sure has a mess on its hands thanks to that Claude Code source leak
2026-04-06T07:24:03Z•4f9ccfa740149750738d5682da0e661d12506020a4780f0a1b0031a73996e58d
anthropicaxios backdoorchatgptcitrix netscalerclaude source leakcredential theftcredential-stealerdns exfiltrationenterprise securityghostsocksiran-linked actorslitellmmalwarenpmopenaipassword-sprayingpypiremote-access trojansoftware-supply-chainsupply-chain attacktelnyx pypitrivytrojanized downloadsvidar
What happened
Feed of infosec headlines highlighting multiple high-risk incidents: Anthropic accidentally released Claude source code and many downloads were later found trojanized with credential stealers (reported Vidar) and GhostSocks, putting users and secrets at risk. Related supply‑chain attacks are proliferating — Trivy/LiteLLM fallout, PyPI Telnyx poisoning, and a backdoored axios npm release dropping a RAT — exposing developers and CI environments. Other notable items: in‑the‑wild exploitation of a critical Citrix NetScaler bug, an OpenAI ChatGPT DNS exfiltration flaw that was patched, breaches at:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 4f9ccfa740149750738d5682da0e661d12506020a4780f0a1b0031a73996e58d
- Enrichment time
- 2026-04-06T07:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.