Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
The Ruby vulnerability is not easy to exploit, but allows an attacker to read sensitive data, start code, and install ...