CrowdStrike's October 9 blog tied ARTEX, a Chinese open-source pentesting tool by Li Puhua ('Autumn') on GitHub since July, to a breach of at least seven South Korean financial institutions, 68,000 people's data compromised.
Investigators traced ARTEX by its HTML tag signature in C2 server headers and found an exposed CLAUDE.md with a Chinese-language pentesting prompt. The attacker, believed to be a South China University of Technology student, was caught after leaving directory listing enabled, exposing Claude Code sessions where they asked the AI to add the hack to their résumé.