Tag: npm package malware
1 article

Malicious npm Package Targets Claude AI User Files via GitHub
Disguising itself as a harmless archive deployment sync tool, the malicious npm package mouse5212-super-formatter secretly synced local workspace files to a remote tracking tree, allowing attackers to target user files on GitHub.