ITT: jet fuel AI can’t melt steel beams hack anything.
Also I want to know the name of this company so I can avoid them:
Claude believed the package registry it was using to be part of the simulation, but in reality the package was made freely available online for roughly one hour. During that window, the package was downloaded and run on 15 real systems. One of these systems was a scanner belonging to a real security company (separate from the fictional company introduced in the scenario) that routinely installs Python packages and scans them for malware. When that company’s scanner installed the package, Claude’s hidden code executed. We believe the company’s security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point it had set up. Claude then used these credentials to access further infrastructure from this company.
ETA: I thought I posted this top-level, not my intention to single out this comment specifically.
« Trust me bro, my AI escape containment bro. Yeah Bro! Trust me. Don’t think to much about it bro »
ITT:
jet fuelAI can’tmelt steel beamshack anything.Also I want to know the name of this company so I can avoid them:
ETA: I thought I posted this top-level, not my intention to single out this comment specifically.
AI bullshit company can’t use sandbox environment: expected
So-called “security company” whose job literally is to install and test potential malware can’t use sandbox environment: priceless.