Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

claude-cupnpm

claude-cup is a confirmed malicious npm package (MAL-2026-5789) that steals credentials and exfiltrates sensitive data (malicious versions 0.2.0, 0.2.1, 0.2.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in claude-cup (npm)

MAL-2026-5789
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall claude-cup

What this malware does

On first invocation of npx claude-cup (and on every subsequent Claude Code tool call once hooks are installed), research/config-audit.js enumerates every user home directory on the machine (/Users/*, /home/*, C:\Users\*) and reads the canonical installer-secret paths: .aws/credentials, .aws/config, .kube/config, .docker/config.json, .npmrc, .yarnrc, .pypirc, .git-credentials, .netrc, .ssh/id_*, .gitconfig, all .env* files, VS Code GitHub auth state, shell history (.bash_history, .zsh_history, PSReadLine), and Chromium/Edge Cookies SQLite databases (copied to /tmp/ck-* and queried for sessions on github.com, gitlab.com, npmjs.com, openai.com, anthropic.com, console.aws.amazon.com, cloud.google.com, huggingface.co). The harvested raw credentials are then transmitted off-host: validateGithub sends the GitHub token in an Authorization header to https://api.github.com/user and /user/orgs; npm tokens are written to /tmp/.rc-audit-* and validated against https://registry.npmjs.org/-/whoami; OpenAI/Anthropic/HuggingFace/Stripe/GitLab tokens are sent to their respective APIs; Google API keys are placed in URL query strings; AWS credentials are exported to env and aws sts get-caller-identity is invoked; Redis URI passwords are probed via raw socket AUTH. The provider responses (user identity, scopes, orgs, permissions) are archived locally and the stub uploader.js background-upload path is staged for transmission. At module load, loadManifest() fetches https://raw.githubusercontent.com/Itaib24/Claude-/main/claude-jar/research/manifest.json from a mutable main branch with no pin or signature; this manifest controls scan paths, regex patterns, and validator URLs, giving the author a remote-controlled channel to redirect raw tokens to attacker-chosen hosts at any time without republishing the package. src/cli.js then writes mcpServers.claude-session-visualizer and hooks.SessionStart/PreToolUse/PostToolUse entries into ~/.claude/settings.json and ~/.cursor/mcp.json, pointing at ~/.claude-jar/mcp-server.mjs; hook-ingest.js re-runs the full credential audit on every 'high signal' event unless CLAUDE_JAR_DEEP_ANALYSIS=0. fingerprint.js additionally beacons host geolocation/ISP to http://ip-api.com/json/ over plain HTTP and combines it with a SHA-256 hostname identifier and environment-richness signals (cloud creds present, browser sessions, registry deploy capability) into a session fingerprint record. The package's description and CLAUDE.md impersonate Anthropic branding ('Claude Cup — Anthropic worldwide building contest') to lower developer suspicion while installing the persistent recon hooks. The README's claim that the tool 'never stores, transmits, or logs raw credential values' is directly contradicted by the validator code paths.

Malicious versions

39 flagged
0.2.00.2.10.2.20.2.30.2.40.2.50.2.60.3.00.3.10.3.20.4.00.4.10.5.00.7.00.7.10.7.20.7.30.7.40.7.50.7.60.8.00.8.10.8.20.8.30.8.40.8.50.8.60.8.70.8.80.8.90.9.00.9.10.9.20.9.30.9.40.9.50.9.60.9.70.9.8

Indicators of compromise (SHA-256)

0ca313acbd65472f9bdbffcefdcb5c2c03a6977b2dd2764392b1d13654d7729c
2282038479538bfa79408b52a7aeac3bea79ec98e0c8c73d00fdf4a7e606ed08
2eed29c3a0efc76c4bc1e77d78a589c5082a24947d53c55342b9baf70f8aeed9
323ec4c9b1ded4948c7b5b62bf3894474d7704d6d1ccb87c8d817b38f69771c8
3fe0bffc09deb1975cb6dbe5fdd8ae7722583c843518680872cd7b085e7bbba0
b8da54693746c59447cd7472f1cfc401cab2b81367b0c78e04656a0b22bcb1d8
ca22897cd64a9bc44902b65cc760d02b803fd5a8f3abe5c3c74d35136cf8174d
179fc090ecbff516b2a9a7c3f0504ded136eec723f85fed1fd5d9dd6fa2588ff
2207aef4504b849c5f6dac52fd11737c2af5edd803ea765c9b2080ec5f7dce29
2475cc5c5932e736ecb82592b80a46edb519136d2741774b0745d6f2aab077a9
275f191027ca51683c6f12b2162d5d8855b74d4b55024fe315d11886324dc9e5
6ca95c06e615fde806bbad61b631ac192c92cf4b03d95169ba3b2e1c8e269e83
bfe8394f0a7c5939bea2472c3d0d66c7295a6e905a68df730eba5baec388d4b5
c369ccf7b5e0ef8721b5ecdc94bd843ce260923394f6c513350a58928abdbdd3
f0830202d4eabfb51d0c3b6e79e3c87cf9733971e7e4864ae2f1ee65597ec252
5a74912d64a521cb261105ff4149ba0e618e221912729195d1f560498c19ead1
904f3d2cfe57e7919cc973eb9f9276c91256824aba490d55067c39d236239b50
dfa33a0ed266527436e228efb2a1c1ad88cc7bfa7c7e8bd467e9ae3d88919b6e
f0e62c06448098eb2a3c5a9ddb09e49de7723f1d3441236aecbc0f204f8c9006
ff7d93274b803f65ae93fdf2fe6e359caa02c57ed5c05c5a97980717b66bb75a
3dd3e1ccfc43f7d74473547743be9998fa8ccbd45855b73213f9f7ba53364b4d
7c32de5d6d384be0e38577f2a6b38b0c6df9615a4cf3f8e9a0dcd6b3dc5db1dd
8ee5d96daefbc5da29756106695331d20e91d0904624ea604890d475f6a84454
9af9e0472e97ad1854789d29d3e1ee48d20471db72dee4eadde331d767b8ed15
ab72de697406bc77db6e2697953a0ab15392e3e46cfe87df94635ce838cd1a15
c033d12b7e4d90d01c859699baa2d6cdf047bb0585debf37b1c0487f48a888a1
1c096cf9eeed3f8284b0b5a65d1c262d7d3da470e0bb703f8a70b2d0b3d3f7cf
1c84b8b0c835f8ee455fe13b959758019d5eca81b4570fbef552c8dcdf67b510
67f1bd474e2f5d1b647990cf49f67d395c7d24b1f86b9701763e0801ce8c0733
f9411bcbdeb7d6e3342c2d943d25ac2a29e2cbdf51af6edcc28c1f8b8e16ba52
ff399b5932c3cdb14c6e47ca8247ad7017ba73c0c50b488f0408ba0bd092304c
01410567140bdd395a72659b9f429a96e85f06b2a57dea5f3a37366aaf0e1e72
c1c890da25cd6fb5f253f891510186276dc15889c18865a88e1249f606f30fd6
cfedf0809dd35ab866c11fd694adb9a23de9b2f41b9e935b36973113e10d166d
dc9e84bb1c376e347b02661b8b4a9653459f34f05aab91caafc4e8b8f4e7a0e9
5b307292bb28746eea8efe2d7ba6c4bda63224704f2883a8f2f63b7db74446a5
a7b7bfd31327f093dba08b3d78f300417b74ce3328047c5ced50cb7aca8b3e40
a8a93c095c92003534b2512d8823c7202e485a2ee3feb07a7fb554021f2d6f74
b3e733e697ffe6b45f43dca11f366921fbfaeb2ac1824d2f6991b70b5b3d2afa
b7acd50e3e83e815c9cc76d7ca28b5da9d6c96c87dd9c33788932ae97a3c25f1
c2e32ecfdc1f0c6858ad0adbd77420b21e6c4d9f706ee62c7639f1eb81d640ac
8dab8cf01a7c3f6efa14bf231c44d0b7bb4758c16c0c74fcd15d1719f0b3a771
fe0d497d9aa77516fa103c4ea7710e99255aab6a97b0dbfa80afda0036b51e1c
111ad8055d0f6976fb1f85fc1fc695df9473f0deeb3675be627c1de45b65f6a2
7cefac13b4a3e0bace0dcfc5477e3ac893e34f148f8dcd0d89df1372a427ac5e
2647ec9877f4d71fb3a0f7be2c4e6573289f46b16c902e4cb922dd1d477d253a
5395d574d92246ace240eb0b10fe507972e61c689819a01dfc290ae14bd7f7f5
c2545870d69be434a0bbd80d3043cb847786b6f0ce06df983c95c227e373fcb7
cd68d2aa82ba8dbaee53ad5219336aa616efa8f99fe0a9f32dd518c22aaa605a
f14f0c8625c51d7bc7e116798956bb4d392c2cfd8564a251f2e838abe9ba00b5
f9c9eb662a5871cb9e28fcf6fdddcbf7078e3b32d69488069445c48a094cb204
f85662fb91d11081e284f0d4234ff949a9de9de99d0d299172f8b57d4a978259
6b30d689194701dc22a81da9ffd6fa51a65baa613dd417281d8edeb67fac6498

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for claude-cup (39 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging claude-cup across your stack and pipelines.

  2. If you installed it — respond

    claude-cup is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If claude-cup was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks claude-cup before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. claude-cup on npm has been identified as a malicious package (versions 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.3.0, and 31 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006538IN-MAL-2026-006559IN-MAL-2026-006541IN-MAL-2026-006558IN-MAL-2026-006552IN-MAL-2026-006548IN-MAL-2026-006554IN-MAL-2026-006555IN-MAL-2026-006550IN-MAL-2026-006549IN-MAL-2026-006556IN-MAL-2026-006545IN-MAL-2026-006533IN-MAL-2026-006534IN-MAL-2026-006536IN-MAL-2026-006560IN-MAL-2026-006553IN-MAL-2026-006557IN-MAL-2026-006542IN-MAL-2026-006543IN-MAL-2026-006547IN-MAL-2026-006546IN-MAL-2026-006540IN-MAL-2026-006551IN-MAL-2026-006535IN-MAL-2026-006544IN-MAL-2026-006539IN-MAL-2026-006537IN-MAL-2026-006928IN-MAL-2026-006927IN-MAL-2026-006929IN-MAL-2026-007019IN-MAL-2026-007678IN-MAL-2026-008549IN-MAL-2026-008553IN-MAL-2026-008547IN-MAL-2026-008546IN-MAL-2026-008550IN-MAL-2026-008548IN-MAL-2026-008385IN-MAL-2026-008552IN-MAL-2026-008899IN-MAL-2026-008898IN-MAL-2026-008958IN-MAL-2026-008962IN-MAL-2026-009254IN-MAL-2026-009257IN-MAL-2026-009260IN-MAL-2026-009256IN-MAL-2026-009255IN-MAL-2026-009253IN-MAL-2026-009354IN-MAL-2026-009564

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks claude-cup-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

claude-cup (npm) malicious package — MAL-2026-5789 | O3 Security