PulseAugur
中
实时 05:45:13
English(EN) A Supply-Chain Worm Wrote Itself Into Claude Code's Hook Files to Survive Credential Rotation

供应链蠕虫利用 Claude Code 和 VS Code 配置实现持久化

一个复杂的供应链蠕虫,被称为 ChainDrop 或 Mini Shai-Hulud,已感染超过 400 个 npm 包,窃取了开发者和 CI/CD 环境的凭证。该蠕虫独特地利用窃取的 GitHub 凭证,将恶意配置文件直接注入到 Claude Code 的 `.claude/` 目录和 Visual Studio Code 的 `.vscode/` 目录中。这使得恶意软件在开发者在这些工具中打开受影响的存储库时能够持久存在并自动重新执行,从而绕过了凭证轮换等标准的事件响应措施。 AI

影响 凸显了针对 AI 编码助手的全新攻击向量,需要为开发者工具制定新的安全措施。

排序理由 该项目详细介绍了一种针对特定开发者工具的恶意软件的新型持久化机制,而不是来自前沿 AI 实验室的新发布。

在 dev.to — Claude Code tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

供应链蠕虫利用 Claude Code 和 VS Code 配置实现持久化

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该项目详细介绍了一种针对特定开发者工具的恶意软件的新型持久化机制,而不是来自前沿 AI 实验室的新发布。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
45 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. dev.to — Claude Code tag TIER_1 English(EN) · Ramdai Bista ·

    供应链蠕虫病毒自行写入Claude代码的钩子文件以在凭证轮换中生存

    <p>Rotating your credentials and removing a poisoned package is supposed to end an npm supply-chain compromise. In early August 2026, one worm made sure it didn't have to.</p> <h2> What happened </h2> <p>Microsoft's security research team tracked a campaign it calls "ChainDrop" —…