# mouse5212-super-formatter — AI-Generated Malicious npm Package Exfiltrating Anthropic Claude AI /mnt/user-data Sandbox to Attacker GitHub Repository (Malware-Slop Campaign)

> OX Security uncovered a malicious npm package, mouse5212-super-formatter, that masquerades as an internal 'archive deployment sync' utility but recursively exfiltrates the contents of Anthropic Claude AI's /mnt/user-data sandbox to a threat actor-controlled GitHub repository via the GitHub Contents API. The package executed during the npm postinstall lifecycle hook, authenticated to GitHub using either a victim-environment GITHUB_TOKEN or a hardcoded fallback Personal Access Token, base64-encoded each file, and uploaded it into a per-session random folder. The hardcoded fallback token leaked the attacker's GitHub identity, allowing OX to enumerate approximately seven exfiltration events before the account was deleted. The package reached 676 downloads across versions 1.0.0 through 1.0.4 (published 2026-05-26, unpublished 2026-05-27) and is assessed by OX as an AI-generated 'malware-slop' campaign — likely LLM-authored code with sloppy operational security, a pattern researchers warn will scale.

- **Published:** 2026-05-28T00:00:00Z
- **Last reviewed:** 2026-05-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0621
- **ID:** TL-2026-0621
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** RESOLVED
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Overview

mouse5212-super-formatter is a malicious npm package discovered by OX Security researchers Moshe Siman Tov Bustan and Nir Zadok and disclosed on 2026-05-27 under the codename 'Malware-Slop.' The package is purpose-built to harvest files from Anthropic Claude AI's `/mnt/user-data` sandbox — the directory Claude uses to handle user uploads, downloads, and code/data outputs — and exfiltrate them to a GitHub repository owned by the attacker. Five versions (1.0.0 through 1.0.4) were uploaded to the public npm registry on 2026-05-26 and aggregated 676 downloads before the maintainer unpublished the package on 2026-05-27. The associated GitHub account was created on 2026-05-26, only hours before the first npm publish, and has since been deleted.

## Targeting

The malware specifically targets `/mnt/user-data`, the sandbox path Anthropic mounts inside Claude's code-execution environment for file uploads and code/data outputs. Files written there typically include user-supplied source code, datasets, credentials accidentally pasted into prompts, intermediate analysis artifacts, and the contents of files Claude has been asked to operate on. Any developer who installed mouse5212-super-formatter inside a Claude sandbox (for example, while having Claude install npm dependencies in a coding workflow) would have had the full sandbox state exfiltrated. The Register's reporting recommends that any user who installed the package immediately revoke GitHub access tokens and treat all `/mnt/user-data` contents as compromised.

## Exploit Chain

1. **Initial Access — Supply Chain Compromise.** The attacker registers an npm account and publishes mouse5212-super-formatter (versions 1.0.0–1.0.4) on 2026-05-26. The package presents itself as an internal 'archive deployment sync' utility.
2. **Execution — postinstall lifecycle hook.** When a victim runs `npm install`, the package.json `scripts.postinstall` field executes the malicious JavaScript automatically, without further user action.
3. **Authentication — environment token or hardcoded fallback PAT.** The script first attempts to read a GitHub token from the victim's environment variables; if absent, it falls back to a hardcoded GitHub Personal Access Token belonging to the attacker. This fallback is the OPSEC failure that enabled OX to attribute the campaign.
4. **Resource Development — repository provisioning.** Using the GitHub REST API, the script checks whether the attacker's target repository exists. If not, it creates the repository on the fly.
5. **Discovery and Collection — recursive walk of /mnt/user-data.** The script enumerates the Claude sandbox directory recursively, reading every file it can access.
6. **Defense Evasion — base64 encoding and random folder names.** Each file is base64-encoded (required by the GitHub Contents API for binary content). Files are uploaded into a per-execution random folder name so that multiple stealing sessions remain distinguishable to the operator. Comments and commit messages are 'intentionally bland' English to avoid the telltale verbosity or Russian-language artifacts that often expose LLM-generated malware.
7. **Command and Control / Exfiltration — GitHub Contents API.** Files are uploaded with HTTP PUT requests to `https://api.github.com/repos/{owner}/{repo}/contents/{path}`. This dual-uses the GitHub web service for both C2 (token validation, repo existence checks, repo creation) and exfiltration (file uploads).
8. **Cover Story — fake network status log.** Alongside the stolen files, the script writes a fake 'network connections' log to the repo, intended to make the activity look like benign diagnostic telemetry rather than data theft.

## OPSEC Failure and Attribution

The hardcoded fallback PAT was embedded in plaintext in the package's JavaScript. OX Security extracted the token, used GitHub API endpoints to identify the owning account, observed approximately seven distinct exfiltration sessions (each represented as a random folder under the same destination repo), and published the findings. The attacker's GitHub account had been registered on 2026-05-26 (the same day as the npm publish), and OX additionally notes the operator first tested the stealer logic against a 'test' repository before going live — additional evidence of a hurried, AI-assisted workflow rather than a polished tradecraft.

## AI-Generated Malware Signal

OX Security attributes the code to LLM authorship based on several indicators: structurally clean function decomposition with no human-style idiosyncrasies, consistent JSDoc-style commentary, the choice of a long English package name with a stylistically odd numerical infix ('mouse5212'), and the failure to redact secrets — a class of mistake characteristic of an operator copy-pasting model output without review. OX explicitly frames the campaign as the leading edge of an emerging 'malware-slop' trend: low-effort, LLM-generated supply-chain malware that will proliferate until npm-side automated detection catches up. The Register's coverage echoes the framing and notes that the malware avoids the usual AI tells (redundant comments, Russian-language artifacts) but still leaked its operator identity in the most basic way possible.

## Affected Population

npm reports 676 download events across the five versions. OX cautions that not all downloads correspond to actual installs (mirrors, scanners, and CI dry-runs inflate the count), but every successful `npm install` of an affected version inside an environment with `/mnt/user-data` accessible would have triggered exfiltration. The package has been unpublished from npm, but developers should audit lockfiles for any of the five malicious versions and rotate any tokens that may have been present in the affected sandbox.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1546 Event Triggered Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1552 Unsecured Credentials
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1102 Web Service
- T1573 Encrypted Channel
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel

## Sources

- [Malware-Slop: New Malicious npm Package Leaks Its Own GitHub Private Token](https://www.ox.security/blog/malware-slop-new-malicious-npm-package-leaks-its-own-github-private-token/)
- [Malicious npm Package Stole Files From Claude AI User Directory via GitHub (The Hacker News)](https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html)
- [Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token (The Register)](https://www.theregister.com/2026/05/27/supply-chain-brain-drain-npm-attacker-foolishly-leaks-own-github-private-token/)
- [mouse5212-super-formatter — npm registry metadata](https://registry.npmjs.org/mouse5212-super-formatter)
- [GitHub REST API — Create or update file contents (Contents API endpoint abused for exfiltration)](https://docs.github.com/en/rest/repos/contents)
- [npm CLI documentation — scripts and lifecycle (postinstall)](https://docs.npmjs.com/cli/v10/using-npm/scripts)
- [MITRE ATT&CK T1195.002 — Supply Chain Compromise: Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK T1567.001 — Exfiltration Over Web Service: Exfiltration to Code Repository](https://attack.mitre.org/techniques/T1567/001/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0621
