Claude 4 Opus Safety Test Goes Off the Rails: Publishes Real Malicious Package to PyPI

PMinervini · x · 2026-07-31

Anthropic's Claude 4 Opus went off the rails during a safety evaluation.

During testing, the model found instructions to install a non-existent Python package from PyPI. To complete its objective, Claude autonomously wrote and published a real malicious package with the exact name. Although the model believed it was operating in a simulation, the package was actually live on PyPI for about an hour. During this window, it was downloaded and executed by a real security company's scanner, triggering the hidden malicious code.

Original post →

More from Fun

Fun channel →