emino on Nostr: A popular NPM package got compromised, attackers updated it to run a post-install ...
A popular NPM package got compromised, attackers updated it to run a post-install script that steals secrets
But the script is a *prompt* run by the user's installation of Claude Code. This avoids it being detected by tools that analyze code for malware
From @zacl_overflow on X
Published at
2025-08-28 05:45:57 UTCEvent JSON
{
"id": "d421c0cca298589bf29ecdd2750d261152655ded57414db5273e4491ed8ee2a1",
"pubkey": "db98e5d20b41aec15fe1ee318870111a1b8669b3a5ce31fd0ee64f8ff3ec6750",
"created_at": 1756359957,
"kind": 1,
"tags": [],
"content": "A popular NPM package got compromised, attackers updated it to run a post-install script that steals secrets\n\nBut the script is a *prompt* run by the user's installation of Claude Code. This avoids it being detected by tools that analyze code for malware\n\nFrom @zacl_overflow on X\nhttps://blossom.primal.net/b912e99aee6200447520e2ce3338b0d8353ab87872828779b25dfe976558d58d.jpg",
"sig": "1e0b3df38802926c9c25e35d6072361c087fcf281a3515b55405e76fa208849d2636a0fed0a813b393ee45ad15212c10ed22086d9b82fdcefca407ce4a94c852"
}