A threat group planted a malicious npm package in a crypto trading project through an AI-generated commit by Anthropic's ...
Researchers say the campaign targeted developer credentials and cloud secrets while abusing trusted publishing and AI coding ...
Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.