Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
The now‑patched flaw allowed authenticated users to execute arbitrary code via crafted git push requests, affecting ...