
Unclaimed package names: Claude and Codex ran a stranger's code inside Fortune 500 networks
Alon Hertz registered package names that corporate docs told AI agents to install. Claude, Codex and Hermes fetched and ran the code within the hour.

Alon Hertz registered package names that corporate docs told AI agents to install. Claude, Codex and Hermes fetched and ran the code within the hour.

Two malicious lightning releases hit PyPI on April 30. The 42-minute window was enough to ship an RSA-encrypted infostealer to ML developers worldwide.

Socket flagged a self-propagating worm in @automagik/genie, pgserve, and 14 sibling Namastex Labs packages. It steals 40 credential categories and republishes itself.

A malicious @bitwarden/[email protected] hit npm on April 22. The payload steals npm tokens, cloud secrets, and Claude Code credentials, then self-replicates.

A Carnegie Mellon study counted 6 million suspected fake stars across 18,617 GitHub repos. Here's what the StarScout research actually found and how to read a star count now.