Malicious npm package downloaded 676 times stole Claude AI files via GitHub uploads, increasing AI-driven malware risks.
Somewhere inside GitHub, a developer installed a Visual Studio Code extension. It looked like any other productivity plugin ...