SShortSingh.
Back to feed

npm Supply-Chain Worm Persisted in Repos by Hijacking Claude Code Hook Files

0
·1 views

In early August 2026, a supply-chain attack dubbed 'ChainDrop' compromised an npm maintainer account and pushed malicious code into over 400 packages, harvesting developer credentials from CI/CD and cloud environments. Microsoft's security research team found the worm used stolen GitHub credentials to silently commit malicious hook and config files directly into victims' repositories. Because Claude Code automatically executes hooks defined in '.claude/settings.json' at session start without prompting users for trust confirmation, the malware could re-activate even after developers rotated credentials and removed the poisoned packages. Similar files were planted for VS Code's task runner, indicating the technique is not specific to Claude Code but applicable to any tool that auto-executes repo-level config. Microsoft's analysis identified the targeted credential categories and persistence logic, though a widely circulated figure on the scale of stolen secrets could not be independently verified.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

CTF Challenge Shows How HTTP Request Smuggling Bypasses Path-Based Access Controls

A web challenge from BrunnerCTF 2026 demonstrated a classic CL.TE HTTP request smuggling vulnerability in a simulated internal wiki application. The target page, /wiki/internal/flag, was hinted at via robots.txt but returned a 403 Forbidden response to direct access. The exploit worked because the front-end proxy honored the Content-Length header while the backend Kestrel server prioritized Transfer-Encoding: chunked, causing the two layers to disagree on where one request ended and another began. By crafting a single POST request containing a smuggled GET for the restricted path, the attacker bypassed path-based authorization middleware that only applied to externally routed requests. The smuggled request reached Kestrel directly on the same keep-alive connection, returning the internal article and the hidden flag.

0
ProgrammingDEV Community ·

Dev Builds CUBELANDS, a Procedural Open-World Action-Adventure Headed to Steam

An independent developer is building CUBELANDS, an early-alpha third-person open-world action-adventure game planned for release on Steam. The game's core design principle is full procedural generation, where a single seed determines terrain, settlements, cultures, characters, equipment, and even boss designs. Gameplay combines exploration, combo-based combat, and traversal mechanics such as gliding, grappling, swimming, and slope-surfing. Combat features charged and aerial attacks, parries, perfect-dodge counters, and multi-phase procedural bosses. No release date has been announced, with the developer focused on refining the world, combat, and presentation before sharing further progress updates.

0
ProgrammingDEV Community ·

How 22 passing tests missed a minesweeper solver bug that inverted life-or-death guesses

A developer built a minesweeper probability solver, validated it with 22 unit tests and cross-checked it against a brute-force implementation across 8,000 random boards, finding only floating-point-level differences. After integrating the solver into a playable website, roughly 300 games in, the solver flagged six squares as certain mines when only two actually were. The flaw was exposed by a telling anomaly: the per-cell mine probabilities summed to 13.96 on a board that had only 10 mines remaining, violating the mathematical requirement that those probabilities sum exactly to the mine count. The root cause was a mean-field approximation fallback used when a board component grew too large for exhaustive enumeration, producing estimates that were not true probabilities but were still being treated as certain by the finalize function. The case illustrates how a thorough test suite can miss critical bugs if the specific edge-case inputs that trigger a flawed code path are never exercised.

0
ProgrammingDEV Community ·

How Video Streaming Pipelines Work: A System Design Breakdown

A technical explainer on DEV Community walks through the system design behind video streaming, from upload to playback. The piece frames the problem using a relatable scenario: sending a large skydiving video to a friend across the world. It outlines functional requirements for both uploaders and viewers, including resumable uploads, progress tracking, and smooth cross-network playback. The article also highlights non-functional challenges such as handling massive files, connection drops mid-upload, and sudden spikes in concurrent viewers. It argues that naive single-request upload approaches fail at scale, setting the stage for more robust pipeline architectures.

npm Supply-Chain Worm Persisted in Repos by Hijacking Claude Code Hook Files · ShortSingh