Researchers identified a malicious npm package, mouse5212-super-formatter, that posed as an internal archive deployment synchronization utility but acted as an infostealer during its postinstall phase. The package searched the /mnt/user-data directory used by Anthropic's Claude AI environment for uploads and outputs, then recursively exfiltrated files to a threat actor-controlled GitHub repository through the GitHub Contents API. To reduce suspicion, it also generated a fake network connections log that made its activity appear diagnostic.
OX Security said the package had been downloaded about 676 times on npm, although confirmed compromises were limited, and researchers observed roughly seven exfiltration instances in the attacker repository before it was removed, most believed to be operator testing. The malware authenticated with either an environment token or a hardcoded private GitHub token, and that exposed token helped investigators trace the campaign; the attacker account had been created only hours before the first malicious release and was later deleted. Researchers dubbed the activity "Malware-Slop" and warned users to revoke GitHub access tokens and treat files stored in /mnt/user-data as potentially compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A malicious npm package named "mouse5212-super-formatter" was uploaded to npm, masquerading as an internal archive deployment synchronization utility. Its postinstall behavior recursively collected files from "/mnt/user-data" and exfiltrated them to a GitHub repository.
OX Security said the GitHub account used in the campaign was later deleted after the attack. The deletion followed the repository activity used to store exfiltrated files.
Using the leaked GitHub private token, OX Security traced exfiltration activity in the attacker-controlled repository and observed about seven active exfiltration instances. Most of those instances were believed to be the threat actor’s own testing rather than confirmed victim installations.
OX Security reported that the attacker’s GitHub account was created only hours before the first malicious version of the npm package was uploaded. The account was later used to receive exfiltrated files from infected environments.
OX Security publicly disclosed the malicious npm package and dubbed the activity "Malware-Slop," describing how it targeted "/mnt/user-data" used by Anthropic's Claude AI tool for uploads and outputs. At disclosure, the package had an estimated 676 downloads and was still available on npm, though actual installations were unconfirmed.
The npm package page for "mouse5212-super-formatter" shows the package as deprecated, with an author message stating it is no longer supported and directing users to npm support for more information. This reflects a status change on the package listing after the earlier disclosure that it was still available on npm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceox.security
Open sourcetheregister.com
Open sourcenpmjs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.