npm Mirrors Are Becoming Phishing Hosts, Not Just Package Mirrors
A fake Cloudflare CAPTCHA campaign used npm packages and mirror CDNs as trusted-looking web hosting. The packages were not the payload; the mirror URLs were.
6 articles
A fake Cloudflare CAPTCHA campaign used npm packages and mirror CDNs as trusted-looking web hosting. The packages were not the payload; the mirror URLs were.
A wire-level analysis found Grok Build 0.2.93 uploading tracked source code and full Git history independently of what the agent read. Here is what was proven, what changed, and how developers should respond.
Fast takedowns do not protect systems that auto-install malicious packages or extensions in the first minutes after release. Minimum package age turns time into a practical supply chain defense.
A 0DIN proof of concept against Claude Code demonstrates how a clean-looking repository can lead to runtime command execution. The structural risk behind the attack applies to any AI coding agent with shell access.
When DuckDuckGo's AI killed Trump with rabies, the world laughed. When AI coding assistants invent package names, attackers register them. Nobody's laughing then.
GitHub says an employee device was compromised through a poisoned third-party VS Code extension and internal repositories were exfiltrated. Here is the fact-checked breakdown for defenders.