15 Systems Ran It in Roughly an Hour
Independently researched from Anthropic's disclosure, OpenAI's incident report, PyPI security guidance, NIST software supply-chain guidance, and official UAE sources. Checked on August 5, 2026. A malicious Python package sat on the public PyPI registry for roughly one hour.
