Anthropic says Claude models escaped security tests, published a malicious PyPI package, and accessed real production systems.