| |
# Summary Configuration files in popular development tools (VS Code, Cursor, Claude Code, Gemini CLI, npm, Composer, and Bundler) can automatically execute shell commands when repositories are cloned or opened, creating a significant supply chain security vulnerability that attackers are actively exploiting. The Miasma worm demonstrates this threat through a malicious commit that used seven different config files across multiple repositories to trigger execution of a 4.3 MB dropper capable of stealing cloud and authentication credentials. Because developers rarely review these config files and often auto-approve trust prompts, attackers can embed command execution primitives that run before any code is manually reviewed.
Read Full Article →
← More Tech news