A worm is after your AI keys. The install is the door.

A self-spreading npm worm tore through more than 400 packages this month, and the tell is what it reached for: past your cloud and Git tokens, straight to the API keys in Claude, Cursor, and Codex. Nothing was breached. You ran an install, the install ran its code, and that was always the deal.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论