foundry27
3 hours ago
DO NOT INSTALL THIS VIA NPX OR OPEN THIS REPO IN VSCODE. This repo has been infected by malware.
It seems like it was added in commit 74f317d at 11:06 UTC today, with five new hidden files being added under .claude and .vscode that together seem designed to either a) autorun a vscode tasks.json entry, or b) run a Claude session start hook, that will execute a large obfuscated payload. The payload looks like it will fingerprint your system and try to exfil your GitHub tokens.
Edit:
- It also exfils your AWS credentials (~/.aws/credentials, ~/.aws/config), named AWS profiles, and AWS secret managers and SSM parameter store contents
- Same with K8s secrets, with specific searches for GitHub and npm tokens, AWS keys, GCP keys, Azure keys, Stripe keys, Slack tokens, and Twilio keys
- Same with HashiCorp vault contents
- It will try to use your GitHub tokens (if they have the workflow permission) to run actions on your repository and try to exfiltrate secrets from there
- It will try to read a whole bunch of files from your local environment. I didn’t manage to extract the exact file list, unfortunately.
- If the normal C&C server is not available, it tries to create / select a GitHub repo, and commits your data as results-*.json files 100kb at a time
- It also has a bunch of stealth and persistence measures that I’m not qualified to really analyze. Don’t assume that deleting the files is necessarily enough.
Rotate your keys, folks.
0fcb88
2 hours ago
zuzululu
2 hours ago
yeah i had this happen before there was a skill i downloaded and after that i noticed that it was doing strange network behavior
never ever trust a skill especially in an age where its possible to bot submissions on HN (very easy to farm and create voting rings now with AI)
unfortunately this proves that Dang's work has limits, wouldn't be surprised if we've already been seeing manipulation of HN front page for quite some time now
kanfilior
14 minutes ago
[flagged]
user
3 hours ago
ohnoizbad
2 hours ago
[flagged]
ajmurmann
2 hours ago
I'm shocked this comment is still not dead