A worm is after your AI keys. The install is the door.
A self-spreading npm worm tore through more than 400 packages this month, and the tell is what it reached for: past your cloud and Git tokens, straight to the API keys in Claude, Cursor, and Codex. Nothing was breached. You ran an install, the install ran its code, and that was always the deal.
评论
?
参与讨论