Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Malware dev tries to steal Claude users secrets NPM slop, leaks own GitHub token

A malware developer who created malicious NPM packages targeting Claude AI users' secrets accidentally leaked their own GitHub private token in the process. The attack was part of a supply chain campaign, but the developer's sloppiness exposed their identity and credentials. The incident highlights ongoing risks in the open-source ecosystem.

Related stories