Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
The least exciting page in your browser is also the easiest one to vibe-code.
Kindly share this postAccording to Kaspersky telemetry, almost 19,500 malicious packages were found in open-source projects ...