Desk/2025-W35

Week of Aug 25–31, 2025

5 records2 status changes on new evidence1 new findings

What changed in what we know

New findings

Attacks & incidents

Aug 27, 2025
Anthropic reports Claude Code used to run a data-extortion campaign against at least 17 organizations
AttackMisuse reportAnthropic

Anthropic's August 2025 threat intelligence report describes a criminal who used Claude Code to automate reconnaissance, credential harvesting and network intrusion against at least 17 organizations, including healthcare, emergency services, government and religious institutions, then threatened to publish the stolen data. The report also describes North Korean operatives using Claude to obtain and keep remote technical jobs, and a low-skill actor selling ransomware developed with Claude.

Aug 26, 2025
s1ngularity: compromised Nx npm packages used local AI coding CLIs to hunt for secrets
AttackIncidentNx

Attackers exploited a GitHub Actions workflow injection to steal Nx's npm token and publish malicious versions whose install script scanned systems for secrets, attempted to use locally installed AI CLIs such as Claude and Gemini to assist, and uploaded results to public GitHub repositories. Nx reports the packages were live about four hours and has since moved to trusted publishing and mandatory 2FA approval.

Aug 26, 2025
ESET finds PromptLock, ransomware that writes its scripts with a local LLM, later tied to a research prototype
AttackMalwareESET

ESET Research reported PromptLock, ransomware samples uploaded to VirusTotal that use a locally run open-weight model to generate scripts for file discovery, exfiltration and encryption at runtime, and called it the first known AI-powered ransomware. In a September 3, 2025 update, ESET said the authors of an academic study had contacted it and that their research prototype closely resembles the samples, supporting ESET's view that PromptLock was a proof of concept rather than malware used in attacks.

Defense & research