logo

Claude Code’s Accidental Source Leak Shows How Fast Attackers Exploit Curiosity

ID: 97a9f034-1d56-518b-a6b5-6d8315f4f9c1

STIX ID: report--97a9f034-1d56-518b-a6b5-6d8315f4f9c1

Feed Name: WatchGuard Secplicity Blog

Threat Score
65/100

Date Published: 2026-04-13

Date Updated: 2026-05-01

Author: Krisaly Enriquez

...
...

**Executive summary:** A source-map included in a public NPM release of Claude Code exposed significant TypeScript source, was widely forked and copied, and attackers rapidly capitalized on the attention by creating fake/upgraded repositories that delivered malware (notably Vidar and GhostSocks), illustrating how release hygiene failures and AI-assisted development can escalate into operational security risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.