DEV Community

Achin Bansal
Achin Bansal

Posted on • Originally published at gridthegrey.com

Malicious npm Package Targets Claude AI Users via Supply Chain Attack

Forensic Summary

A malicious npm package named 'mouse5212-super-formatter' was discovered exfiltrating files from Anthropic's Claude AI user directory by authenticating to a threat actor-controlled GitHub repository. The package disguised itself as a legitimate archive utility while silently uploading all local workspace files during the postinstall phase. Notably, the attacker's poor operational security — including a leaked GitHub token — suggests AI-generated malware with minimal human oversight, pointing to a growing trend of low-skill threat actors leveraging AI to produce supply chain malware.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/malicious-npm-package-targets-claude-ai-users-via-supply-chain-attack/

Top comments (0)