Weaponising Trust Signals: Claude Code Lures and GitHub Release Payloads
A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponised the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.