Threat reportMalwareTL-2026-0621

mouse5212-super-formatter — AI-Generated Malicious npm Package Exfiltrating Anthropic Claude AI /mnt/user-data Sandbox to Attacker GitHub Repository (Malware-Slop Campaign)

highRESOLVED

mouse5212-super-formatter (TL-2026-0621), also tracked as Malware-Slop, is a high-severity malware campaign, first published 2026-05-28. It has no confirmed attribution, affects npm registry (mouse5212-super-formatter maintainer), maps to 20 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-0621

Threat ID
TL-2026-0621
Also known as
Malware-Slop, mouse5212-super-formatter Claude AI stealer
Severity
HIGH
Status
RESOLVED
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, artificial-intelligence, research, developer-tooling
Target regions
Global
Detection rules
9
Indicators of compromise
21

How mouse5212-super-formatter works

OX Security uncovered a malicious npm package, mouse5212-super-formatter, that masquerades as an internal 'archive deployment sync' utility but recursively exfiltrates the contents of Anthropic Claude AI's /mnt/user-data sandbox to a threat actor-controlled GitHub repository via the GitHub Contents API. The package executed during the npm postinstall lifecycle hook, authenticated to GitHub using either a victim-environment GITHUB_TOKEN or a hardcoded fallback Personal Access Token, base64-encoded each file, and uploaded it into a per-session random folder. The hardcoded fallback token leaked the attacker's GitHub identity, allowing OX to enumerate approximately seven exfiltration events before the account was deleted. The package reached 676 downloads across versions 1.0.0 through 1.0.4 (published 2026-05-26, unpublished 2026-05-27) and is assessed by OX as an AI-generated 'malware-slop' campaign — likely LLM-authored code with sloppy operational security, a pattern researchers warn will scale.

## Overview

mouse5212-super-formatter is a malicious npm package discovered by OX Security researchers Moshe Siman Tov Bustan and Nir Zadok and disclosed on 2026-05-27 under the codename 'Malware-Slop.' The package is purpose-built to harvest files from Anthropic Claude AI's `/mnt/user-data` sandbox — the directory Claude uses to handle user uploads, downloads, and code/data outputs — and exfiltrate them to a GitHub repository owned by the attacker. Five versions (1.0.0 through 1.0.4) were uploaded to the public npm registry on 2026-05-26 and aggregated 676 downloads before the maintainer unpublished the package on 2026-05-27. The associated GitHub account was created on 2026-05-26, only hours before the first npm publish, and has since been deleted.

## Targeting

The malware specifically targets `/mnt/user-data`, the sandbox path Anthropic mounts inside Claude's code-execution environment for file uploads and code/data outputs. Files written there typically include user-supplied source code, datasets, credentials accidentally pasted into prompts, intermediate analysis artifacts, and the contents of files Claude has been asked to operate on. Any developer who installed mouse5212-super-formatter inside a Claude sandbox (for example, while having Claude install npm dependencies in a coding workflow) would have had the full sandbox state exfiltrated. The Register's reporting recommends that any user who installed the package immediately revoke GitHub access tokens and treat all `/mnt/user-data` contents as compromised.

## Exploit Chain

1. **Initial Access — Supply Chain Compromise.** The attacker registers an npm account and publishes mouse5212-super-formatter (versions 1.0.0–1.0.4) on 2026-05-26. The package presents itself as an internal 'archive deployment sync' utility. 2. **Execution — postinstall lifecycle hook.** When a victim runs `npm install`, the package.json `scripts.postinstall` field executes the malicious JavaScript automatically, without further user action. 3. **Authentication — environment token or hardcoded fallback PAT.** The script first attempts to read a GitHub token from the victim's environment variables; if absent, it falls back to a hardcoded GitHub Personal Access Token belonging to the attacker. This fallback is the OPSEC failure that enabled OX to attribute the campaign. 4. **Resource Development — repository provisioning.** Using the GitHub REST API, the script checks whether the attacker's target repository exists. If not, it creates the repository on the fly. 5. **Discovery and Collection — recursive walk of /mnt/user-data.** The script enumerates the Claude sandbox directory recursively, reading every file it can access. 6. **Defense Evasion — base64 encoding and random folder names.** Each file is base64-encoded (required by the GitHub Contents API for binary content). Files are uploaded into a per-execution random folder name so that multiple stealing sessions remain distinguishable to the operator. Comments and commit messages are 'intentionally bland' English to avoid the telltale verbosity or Russian-language artifacts that often expose LLM-generated malware. 7. **Command and Control / Exfiltration — GitHub Contents API.** Files are uploaded with HTTP PUT requests to `https://api.github.com/repos/{owner}/{repo}/contents/{path}`. This dual-uses the GitHub web service for both C2 (token validation, repo existence checks, repo creation) and exfiltration (file uploads). 8. **Cover Story — fake network status log.** Alongside the stolen files, the script writes a fake 'network connections' log to the repo, intended to make the activity look like benign diagnostic telemetry rather than data theft.

## OPSEC Failure and Attribution

The hardcoded fallback PAT was embedded in plaintext in the package's JavaScript. OX Security extracted the token, used GitHub API endpoints to identify the owning account, observed approximately seven distinct exfiltration sessions (each represented as a random folder under the same destination repo), and published the findings. The attacker's GitHub account had been registered on 2026-05-26 (the same day as the npm publish), and OX additionally notes the operator first tested the stealer logic against a 'test' repository before going live — additional evidence of a hurried, AI-assisted workflow rather than a polished tradecraft.

## AI-Generated Malware Signal

OX Security attributes the code to LLM authorship based on several indicators: structurally clean function decomposition with no human-style idiosyncrasies, consistent JSDoc-style commentary, the choice of a long English package name with a stylistically odd numerical infix ('mouse5212'), and the failure to redact secrets — a class of mistake characteristic of an operator copy-pasting model output without review. OX explicitly frames the campaign as the leading edge of an emerging 'malware-slop' trend: low-effort, LLM-generated supply-chain malware that will proliferate until npm-side automated detection catches up. The Register's coverage echoes the framing and notes that the malware avoids the usual AI tells (redundant comments, Russian-language artifacts) but still leaked its operator identity in the most basic way possible.

## Affected Population

npm reports 676 download events across the five versions. OX cautions that not all downloads correspond to actual installs (mirrors, scanners, and CI dry-runs inflate the count), but every successful `npm install` of an affected version inside an environment with `/mnt/user-data` accessible would have triggered exfiltration. The package has been unpublished from npm, but developers should audit lockfiles for any of the five malicious versions and rotate any tokens that may have been present in the affected sandbox.

MITRE ATT&CK techniques used in TL-2026-0621

Collection

T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Discovery

T1083 File and Directory Discovery

Initial Access

T1195 Supply Chain Compromise

Persistence

T1546 Event Triggered Execution

Credential Access

T1552 Unsecured Credentials

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1608 Stage Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in mouse5212-super-formatter

  • npm registry (mouse5212-super-formatter maintainer) — mouse5212-super-formatter (npm package)
    Vulnerable versions: 1.0.0; 1.0.1; 1.0.2; 1.0.3; 1.0.4
    Fixed in: unpublished from npm 2026-05-27
  • Anthropic — Claude AI /mnt/user-data sandbox directory
    Vulnerable versions: any Claude code-execution session that installed the malicious package
    Fixed in: package removed from npm; sandbox unaffected when --ignore-scripts is enforced

Remediation for mouse5212-super-formatter

Patches

  • npm has unpublished all versions of mouse5212-super-formatter (1.0.0 through 1.0.4) as of 2026-05-27 — no install path remains via the registry
  • Anthropic Claude AI sandboxes should treat any package install from the public npm registry as untrusted until npm rolls out automated malware blocking

Immediate actions

  • Audit package-lock.json, yarn.lock, and pnpm-lock.yaml across all repositories for mouse5212-super-formatter at any version (1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4)
  • If installed, treat the affected environment as compromised: revoke every GitHub Personal Access Token, fine-grained PAT, OAuth app token, and GitHub App installation token reachable from that environment
  • Treat all contents of /mnt/user-data (or the local equivalent) at time of install as exfiltrated; rotate any secrets, API keys, or credentials that may have been present
  • Remove the package from any caches: npm cache clean --force, and purge offline mirrors and Verdaccio caches
  • Review GitHub audit logs for unexpected repository creations and Contents API PUT activity attributed to revoked tokens

Workarounds

  • Run npm install with --ignore-scripts inside any Claude sandbox or comparable agentic-AI execution environment
  • Pre-scan dependencies with Socket/Snyk before allowing install in a sandbox with sensitive file mounts
  • If immediate install is required, use npm pack and inspect package contents (especially package.json scripts) before execution

Longer-term hardening

  • Block postinstall, install, and preinstall lifecycle scripts in CI by default using --ignore-scripts (npm), enableScripts false (yarn), or ignore-scripts=true (pnpm)
  • Adopt allow-listed dependency installation in sensitive AI sandboxes — pin and pre-vet every npm package before it can run in a Claude /mnt/user-data context or comparable environment
  • Egress-restrict AI code-execution sandboxes so api.github.com is reachable only when explicitly required by the user task, and log every outbound HTTPS request
  • Deploy npm supply-chain monitoring (Socket, Snyk Advisor, Phylum, OX Security) with alerting for newly registered packages installed by internal developers
  • Run secret-scanning hooks (gitleaks, trufflehog) against installed node_modules contents to catch embedded tokens before postinstall execution

Weaknesses (CWE) in mouse5212-super-formatter

CWE-506, CWE-829, CWE-798, CWE-200

Timeline of mouse5212-super-formatter

  • Approximately seven distinct exfiltration sessions land in the attacker repository, each under a randomly named folder; OX traces them via the leaked hardcoded GitHub PAT.
  • Versions 1.0.1, 1.0.2, 1.0.3, and 1.0.4 published within a four-hour window (18:04–18:17 UTC), consistent with hurried iteration on the postinstall payload.
  • mouse5212-super-formatter version 1.0.0 published to the public npm registry at 17:30:57 UTC.
  • OX Security observes the operator first testing the information-stealing logic against a 'test' GitHub repository in the same attacker account.
  • Attacker registers GitHub account that will host exfiltrated files; account is created only hours before the first malicious npm publish.
  • Attacker-controlled GitHub account is deleted, severing access to evidence of stolen files; revoked PAT no longer accepted by GitHub API.
  • mouse5212-super-formatter unpublished from npm at 17:53:41 UTC; total download count at removal is 676 across all five versions.
  • OX Security publishes Malware-Slop research; The Hacker News and The Register pick up the story the same day.
  • As of 2026-05-29, this specific Malware-Slop campaign is neutralized: npm registry metadata confirms all five mouse5212-super-formatter versions were unpublished 2026-05-27, and the throwaway attacker GitHub account is deleted with its hardcoded PAT revoked, killing the exfil sink. The actor is unknown/single-use with no rebrand or successor package reported, though OX warns the AI-generated postinstall-stealer technique class will spawn copycats.

Sources cited for mouse5212-super-formatter

Detection coverage for TL-2026-0621

As of 2026-05-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0621 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats