PulseAugur
中
实时 07:34:48
English(EN) Malicious npm Package Stole Files From Claude AI User Directory via GitHub

恶意 npm 包窃取 Claude AI 用户目录中的文件

发现了一个恶意的 npm 包,它窃取了 Claude AI 用户目录中的文件,特别针对克隆了 Anthropic 的 GitHub 存储库的用户。该包伪装成一个合法的工具,利用漏洞窃取敏感数据。此事件凸显了 AI 开发中第三方软件依赖项持续存在的安全风险。 AI

影响 凸显了 AI 开发供应链中的安全风险,可能影响用户信任和数据安全。

排序理由 第三方包中的安全漏洞影响了 AI 用户。

在 r/ClaudeAI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

恶意 npm 包窃取 Claude AI 用户目录中的文件

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
第三方包中的安全漏洞影响了 AI 用户。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
128 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. r/ClaudeAI TIER_2 English(EN) · /u/sunychoudhary ·

    恶意npm包通过GitHub窃取Claude AI用户目录下的文件

    <!-- SC_OFF --><div class="md"><p><a href="https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html">https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html</a></p> </div><!-- SC_ON --> &#32; submitted by &#32; <a href="https://www.reddi…