AI-Coded npm Package Steals Claude AI User Files — and Leaks Its Own GitHub Token
A malicious npm package targeting Claude AI users' local directories was caught exfiltrating sensitive files to GitHub — while accidentally exposing the attacker's own private token in a textbook OPSEC failure.
Read Article →