Menu

Post image 1
Post image 2
1 / 2
0

Malicious npm Package Targets Claude AI Users via Supply Chain Attack

DEV Community: cybersecurity·Achin Bansal·2 days ago
#6CTLLUvB
#dev#package#malicious#files#claude#threat
Reading 0:00
15s threshold

Achin Bansal

Forensic Summary

A malicious npm package named 'mouse5212-super-formatter' was discovered exfiltrating files from Anthropic's Claude AI user directory by authenticating to a threat actor-controlled GitHub repository. The package disguised itself as a legitimate archive utility while silently uploading all local workspace files during the postinstall phase. Notably, the attacker's poor operational security — including a leaked GitHub token — suggests AI-generated malware with minimal human oversight, pointing to a growing trend of low-skill threat actors leveraging AI to produce supply chain malware.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/malicious-npm-package-targets-claude-ai-users-via-supply-chain-attack/

Read More