25

Seems like a ton (over 1k) of people were affected because of an auto updating VS Code extension. Check your bashrc/zshrc and GitHub account if you use nx

top 2 comments
sorted by: hot top controversial new old
[-] Solemarc@lemmy.world 6 points 1 month ago* (last edited 1 month ago)

This doesn't look like a Claude issue or an AI issue, this looks like someone pushed malicious code to a repo and they where trying to make AI tools ignore these files? I'm not reading this wrong am I?

[-] qqq@lemmy.world 6 points 1 month ago* (last edited 1 month ago)

The command injection in the GitHub action code was written by Claude[1]. That was used to get the NPM key and then malware was pushed to NPM.

[1] https://github.com/nrwl/nx/pull/32458

this post was submitted on 28 Aug 2025
25 points (100.0% liked)

Programming

23023 readers
190 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 2 years ago
MODERATORS