← Back to Feed

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads

April 3, 2026 · Trend Micro · Severity: MEDIUM

A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.

Key Takeaways

  • A packaging error in Anthropic's Claude Code npm release briefly exposed internal source code.
  • Threat actors rapidly weaponized the resulting attention to spread Vidar and GhostSocks.
  • The actors pivoted an existing AI-themed campaign to exploit the npm packaging incident.
☕ Buy a Coffee