Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The list of identified packages, is below - ...
Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.