Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

free-anthropic-claudenpm

free-anthropic-claude is a confirmed malicious npm package (MAL-2026-6260) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 4.7.7, 4.7.9…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in free-anthropic-claude (npm)

MAL-2026-6260
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall free-anthropic-claude

What this malware does

This package impersonates the Anthropic Claude SDK (name and description claim to be an 'Official Anthropic Claude SDK wrapper', author is 'anthropic-tools') but ships a multi-stage dropper. The package.json declares postinstall: node lib/cli.js, which auto-executes on npm install and runs the following chain in lib/index.js:

  1. Hardcoded C2 over bare IPs: POSTs to four hardcoded IP addresses (107.189.20.82, 107.189.20.146, 104.194.134.33, 104.194.133.89) reconstructed from integer arrays, with TLS verification disabled (rejectUnauthorized:false). The JSON response is base64-decoded and written to disk as main.py, then executed via a detached Python process.
  2. Alternate-runtime dropper: if the host lacks a usable Python, the installer downloads Miniconda from repo.anaconda.com via curl/wget into ~/.local/share/prometheus/miniconda (Linux), runs winget install Python.Python.3.12 (Windows), or brew install python3 (macOS) — installing an entire Python distribution solely to run the C2-supplied payload.
  3. macOS privacy bypass: on Darwin, sqlite3-INSERTs rows into ~/Library/Application Support/com.apple.TCC/TCC.db granting kTCCServiceSystemPolicySysAdminFiles / SystemPolicyAppData to Terminal, the running node binary, and /usr/bin/python3 — subverting TCC so the dropped payload has broad filesystem access without user consent.
  4. Crypto-wallet stealer toolchain: pip-installs bip-utils, mnemonic, pycryptodome, psutil, eth-account with --break-system-packages, the canonical libraries for BIP39 seed-phrase parsing, BIP32 derivation, and Ethereum private-key handling.
  5. Persistence: writes a .cs_v2 marker and main.py under disguised paths impersonating system directories (~/.local/share/com.apple.sync on macOS, ~/.local/share/prometheus on Linux, %LOCALAPPDATA%\Microsoft\Windows Security\Health on Windows). Subsequent require() of the package re-spawns the detached Python payload.
  6. Pervasive string-split obfuscation: module names and API calls are reconstructed via ['x','y'].join('') (['htt','ps'], ['child','_pro','cess'], ['exec','Sync'], ['spa','wn'], ['ba','se','64'], module['constr'+'uctor']['_l'+'oad']) to evade static analysis.

The README is for an unrelated 'cachesync-helper' package, further confirming the lure-and-impersonation pattern.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

The OpenSSF Package Analysis project identified 'free-anthropic-claude' @ 5.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

26 flagged
1.0.04.7.74.7.95.0.05.0.15.0.25.0.35.0.45.0.55.0.65.0.75.0.85.0.95.1.05.1.15.1.25.1.35.1.45.1.55.1.65.1.75.1.85.1.95.2.05.3.05.5.0

Indicators of compromise (SHA-256)

01d5845e6a8ba2bca29e99aaed593e5c7616c9ff89eb32d3d319dd65cf1839b0
0e3dad592504bc63710bbb89f27b8bd8d8759416b0b36aa456212150da9ee96f
0f5e41901a37ad58b62cfef52f5bcf37d5e0cc43bac24a00265c14dd5edd5e93
17dc648ff5a235a4385a3b39d586d9312734c154400f8fa92d7504b8ef4f8009
46f0c9ae9e0c3f8b3f874a1c83566da728da0560d17bcb7b09f765099174dacc
489f730f0c0a8727780c1196d5b1bc8a59f64775516eab74854cd342a5e815f8
2e09c0e7ec4edbb3a5c976ff8498e7d651823c9d559bb2ecc9c0a4b39aaa258a
8b5a01c5ead2eb7c9f66e75271515467481a20c7ff9e2b75e5e87f4e17fe86c3
a8fa49b294cafab3885fba950975b69c4aff7e3f661bf4c13654d838a34f975e
9761f8260975a33cd0b2953aefd0f4866a979bb7b86d53f87e9cc8b7bdb41775
ad8218b180c55dd56af28f64835e93dc046faf037c3797eda71e0766bb4e8d31
10aaf93eb627220a6835ab2b099323ffe23a943e45b43c8c743841d7a3438d23
3d8f71589ebe4a3612173a3eecb6f25c357ba10ec70370c6e82622ceee3a9e15
45ac0c1ea4dd642c5d0fe399130f0eb176e283fcfc436c5f3874ba65688185df
df407d9d901a27dede614fa677af0fd3292afec30de7a1bb5fcd7c390e9f94de
c7472d6af491ce5cec3906aab00cb2c31623cc46c4302cabe706e57cbbf588c5
2ad88c4fd6e9ca28a5194fdb21e56fed30e22cef6698cb197930370b14652427
7a9697ec23f824bc0bae8a1a3232780e3a711d1ffba36ff1bd3689a7769d29cc
86f239c8bb1f9778c21aec90ad9fabd42438a3d9aa02023f71b578a224566282
9593f28ec6b46272e1c7a57eaba9fe577770995a451936de47fecc7b2120f651
b4e0d31f48691733115f0f8a627869cd0e23a14ad254fcfa24f217a45096fffb
33e1be1ff9adfbabb5090384919d7c78678062e085896b438029722899bbc4e6
4a0d6dcb9029b29d7d5624f10bfbf583162d716c41920af3d3eac25d23088d17
5af6290ac98ba1963e5515db9677f0b725281e1a14c903271d28c50f33cd3f72
7778d3adf33380f14e67613f660f932c8fdab4aaa3ce2096e14e95c043cc81e8
7c06842ef4209b97801c583d254fd866c7d1966897e2073d5e923b1b11bfe749
e9d1f2cbf92ab992141a9a1192bc70afefc3f09c94550ca985f2c4446fda4996
f1657b6460d2b19b3b6e7b59b4c633f5d2b0e46e4df828f6490601ee8b4549dd
0220e9a9c70f73a4a65b1e01abfb10343499ecfcec7472e1b0792fba8c0863a3
5fdfdca78930c80580a73d74d366ab98445d7f4f8e005330350bb456a739859a
79a5d6efda3af00448daa23c45c1b844be30bd8c331a81798e3d41ecb801b7ec
9657b65164b98daf98cd06746074c63957d2d96b01541919308937bde4015f85
df1216e20aba739766fa6cd1b73f1fc8753920d6f8f82279205d60c207779680
e1cae3fce9d48dcaa9ce7185e646425af03ad5c3cf0107417087f2177a5326a1
11bfe96b56a6615a50639b25de793e14044ea393c2029b26fa4e1b9e3dc5a22f
54047ff2942e7ebb58b56739d25255dcd31e061d13cd75dad0827b2bb5f25a30
7a0550857216d9a92885d368adb727f1b0effa87069cc9da1e15a4c206b17e78
98e3a39410b4d8e22f45a0b57ae410dfe2af657f88976f2bbd7ffa3e57cc94ea
f1e490682c8dd38fd97c90b365eacf71086d64b57af905f96e58490ec35d5e6c
2af991bda2621f4eb3345fa7864245d31a80d16ca27a04782e4dcef114d20f44
40131b3777a1f8c85918e3ab8763ef62839d4e0aa69e5d3b159035819b639a4b
07283b13f9b6aad0bbf18c27d8e254874bec4f1d63c62d6a4821af780e1218fe
586948d225b87308b256ad2ea2ca6f321043554bd059a67000f9f76a223b1b8d

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for free-anthropic-claude (26 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging free-anthropic-claude across your stack and pipelines.

  2. If you installed it — respond

    free-anthropic-claude is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If free-anthropic-claude was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks free-anthropic-claude before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. free-anthropic-claude on npm has been identified as a malicious package (versions 1.0.0, 4.7.7, 4.7.9, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, and 18 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-007115IN-MAL-2026-007122IN-MAL-2026-007135IN-MAL-2026-007128IN-MAL-2026-007131IN-MAL-2026-007134IN-MAL-2026-007117IN-MAL-2026-007124IN-MAL-2026-007133IN-MAL-2026-007114IN-MAL-2026-007125IN-MAL-2026-007119IN-MAL-2026-007130IN-MAL-2026-007129IN-MAL-2026-007120IN-MAL-2026-007126IN-MAL-2026-007121IN-MAL-2026-007123IN-MAL-2026-007127IN-MAL-2026-007116IN-MAL-2026-007132IN-MAL-2026-007118GHSA-3h58-8ch3-mgp3IN-MAL-2026-009444IN-MAL-2026-009448IN-MAL-2026-009547IN-MAL-2026-009545

References

Credits

  • Amazon Inspector · finder
  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks free-anthropic-claude-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

free-anthropic-claude (npm) malicious package — MAL-2026-6260 | O3 Security