Join Nostr
2025-08-28 05:45:57 UTC

emino on Nostr: A popular NPM package got compromised, attackers updated it to run a post-install ...

A popular NPM package got compromised, attackers updated it to run a post-install script that steals secrets

But the script is a *prompt* run by the user's installation of Claude Code. This avoids it being detected by tools that analyze code for malware

From @zacl_overflow on X