
Unclaimed package names: Claude and Codex ran a stranger's code inside Fortune 500 networks
Alon Hertz registered package names that corporate docs told AI agents to install. Claude, Codex and Hermes fetched and ran the code within the hour.

Alon Hertz registered package names that corporate docs told AI agents to install. Claude, Codex and Hermes fetched and ran the code within the hour.

Attackers compromised 42 TanStack packages through a pull_request_target exploit, cache poisoning, and OIDC token theft. An external researcher caught it in 20 minutes.

Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.

A malicious @bitwarden/[email protected] hit npm on April 22. The payload steals npm tokens, cloud secrets, and Claude Code credentials, then self-replicates.

GHSA-xq3m-2v4x-88gg hits protobuf.js ≤8.0.0 / ≤7.5.4. Attacker-controlled schemas executed arbitrary JS on decode. One-line fix patched it.