A French-speaking, financially motivated operator allegedly tied to the ShinyHunters ecosystem used Claude-assisted workflows to harvest credentials from approximately 1.8 million Android APKs and GitHub. Operating under aliases including MeowSHA, frkoo, and blazespider, the actor reportedly used 10 AWS EC2 workers to acquire and decompile applications, then scanned them with TruffleHog for hardcoded secrets. Verified findings were sent to Telegram channels for prioritization, while a parallel effort collected organizational email addresses and searched GitHub for exposed Personal Access Tokens.
Anthropic said the stolen credentials enabled confirmed enterprise intrusions involving cloud-key validation, session replay, token amplification, CI/CD injection, database dumping, and cross-tenant data collection. The company said the abused Claude API keys had been stolen from customer environments—not Anthropic—and that it banned the implicated accounts, improved detection, and coordinated with affected organizations and law enforcement.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Anthropic's September 2026 threat-intelligence report described the alleged financially motivated credential-theft operation and attributed it to a French-speaking operator using the aliases MeowSHA, frkoo, and blazespider.
Anthropic stated that the API keys abused in the activity were stolen from customer environments, not from Anthropic systems. The company banned accounts tied to the operation, improved detection measures, and coordinated with affected parties, industry partners, and authorities.
The actors reportedly dumped more than 2,100 Azure AD token sets across more than 40 corporate tenants in roughly 34 hours. Anthropic said AI agents performed most of the work in this token-theft activity.
In an alleged supply-chain incident, the actors reportedly extracted data from approximately 200 downstream customer organizations after compromising a SaaS provider.
Anthropic said the Android and GitHub pipelines supplied initial credentials used in many confirmed intrusions associated with the operator. Observed activity included cloud-key validation, session replay, token amplification, CI/CD injection, database dumping, and cross-tenant data collection.
A French-speaking operator allegedly associated with the ShinyHunters ecosystem used Claude-assisted workflows and 10 AWS EC2 workers to download, decompile, and scan about 1.8 million Android APKs with TruffleHog. The operation also harvested organization email addresses and sought exposed GitHub Personal Access Tokens, forwarding verified secrets to Telegram channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.