Claude Package Scam: How a Fake SDK Stole Real API Keys A fake Claude package on PyPI, named to closely resemble Anthropic's official SDK, was discovered to be a key stealer that exfiltrated real API keys from developers who installed it. The malicious package was not a typo squat but a deliberate attempt to deceive users into compromising their credentials. Claude Package Scam: How a Fake SDK Stole Real API Keys Fake Claude /en/tags/claude/ package on PyPI wasn't a typo squat — it was a tiny little key stealer.The story: someone named a package so close to the official Anthropic SDK that a lot of people probably didn't think twice before installing it. Once it landed, it Next My 20-Year Friday Call With Bob Charette: A Mentor's Legacy → /en/news/4792/ All Replies (4) F R Almost grabbed it last week too. Only caught it because the repo link looked slightly off. 0