Two security campaigns this week highlight how trust has become the primary attack surface in the AI era. The group TeamPCP has injected malicious code into over 1,000 open-source packages in four months, affecting high-profile victims like Bitwarden, Red Hat, and GitHub, with poisoned packages accumulating roughly 500 million downloads per week. AI coding agents worsen the problem by autonomously installing packages with little or no human oversight. Separately, attackers abused Anthropic Claude's 'Shared Chats' feature to stage fake Apple Support conversations on claude.ai, then used Google ads to lure macOS developers into running malicious terminal commands — compromising over 2,000 victims. The common thread: attackers exploit trusted systems rather than breaking through defenses, making 'legitimate' no longer synonymous with 'safe'.

3m read timeFrom thenextweb.com
Post cover image
Table of contents
1,000 poisoned packagesAI makes it worseEven Claude became a weaponWhy it matters
357 Impressions