npm Supply-Chain Worm Persisted in Repos by Hijacking Claude Code Hook Files
In early August 2026, a supply-chain attack dubbed 'ChainDrop' compromised an npm maintainer account and pushed malicious code into over 400 packages, harvesting developer credentials from CI/CD and cloud environments. Microsoft's security research team found the worm used stolen GitHub credentials to silently commit malicious hook and config files directly into victims' repositories. Because Claude Code automatically executes hooks defined in '.claude/settings.json' at session start without prompting users for trust confirmation, the malware could re-activate even after developers rotated credentials and removed the poisoned packages. Similar files were planted for VS Code's task runner, indicating the technique is not specific to Claude Code but applicable to any tool that auto-executes repo-level config. Microsoft's analysis identified the targeted credential categories and persistence logic, though a widely circulated figure on the scale of stolen secrets could not be independently verified.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in