Live Thursday, 18 June 2026
BREAKING
Egyptian FM holds calls with Iranian counterpart , U.S. Envoy on regional developmentsZverev into French Open last-fourIsraeli fire kills four people in Gaza, medics sayAncelotti eases Neymar W. Cup fearsArab, Islamic states condemn Israeli actions at Al-AqsaSyria Hopes for Terrorism Delisting to Spur Economic RecoveryBenfica linked with Fulham’s SilvaVan der Breggen takes Giro leadKremlin: Saudi Arabia Named Guest of Honor at St. Petersburg Economic Forumرياضة محلية‘Really cool to share this journey with her’: Michelle Wie West playing for her family at U.S. Women’s OpenArchaeological Replicas Showcase Saudi Arabia’s Rich History at Kuala Lumpur Int’l Book FairRenewable Energy Helps Red Sea Global Avoid 118,000 Tons of Carbon EmissionsLetter: Carol Rumens obituaryEngland v India: third and deciding women’s T20 cricket international – liveHealthVolunteers serve comfort food in a worrying Ebola outbreak – Sault Michigan NewsEconomyTrump signs AI executive order asking companies to give government early access to modelsVarietySouth West Water fined nearly £2million after supplying homes with parasite-ridden water that left four people in hospital – and telling people it was safe to drinkScience & TechYour car is following you – how to reclaim your data privacy on the open roadWorldHigh school valedictorian yanked from stage after hijacking speech to rant against Israel and ICESaudi FM Receives Written Message from Russian CounterpartEgyptian FM holds calls with Iranian counterpart , U.S. Envoy on regional developmentsZverev into French Open last-fourIsraeli fire kills four people in Gaza, medics sayAncelotti eases Neymar W. Cup fearsArab, Islamic states condemn Israeli actions at Al-AqsaSyria Hopes for Terrorism Delisting to Spur Economic RecoveryBenfica linked with Fulham’s SilvaVan der Breggen takes Giro leadKremlin: Saudi Arabia Named Guest of Honor at St. Petersburg Economic Forumرياضة محلية‘Really cool to share this journey with her’: Michelle Wie West playing for her family at U.S. Women’s OpenArchaeological Replicas Showcase Saudi Arabia’s Rich History at Kuala Lumpur Int’l Book FairRenewable Energy Helps Red Sea Global Avoid 118,000 Tons of Carbon EmissionsLetter: Carol Rumens obituaryEngland v India: third and deciding women’s T20 cricket international – liveHealthVolunteers serve comfort food in a worrying Ebola outbreak – Sault Michigan NewsEconomyTrump signs AI executive order asking companies to give government early access to modelsVarietySouth West Water fined nearly £2million after supplying homes with parasite-ridden water that left four people in hospital – and telling people it was safe to drinkScience & TechYour car is following you – how to reclaim your data privacy on the open roadWorldHigh school valedictorian yanked from stage after hijacking speech to rant against Israel and ICESaudi FM Receives Written Message from Russian Counterpart
Prices
US dollar49.93EGPEuro57.68EGPBritish pound66.74EGPSaudi riyal13.31EGPUAE dirham13.60EGPKuwaiti dinar162.35EGPJordanian dinar70.42EGPQatari riyal13.72EGPTurkish lira1.08EGPChinese yuan7.37EGPGold 246,888.92EGP/gGold 216,027.80EGP/gGold 185,166.69EGP/gSilver110.13EGP/g
US dollar49.93EGPEuro57.68EGPBritish pound66.74EGPSaudi riyal13.31EGPUAE dirham13.60EGPKuwaiti dinar162.35EGPJordanian dinar70.42EGPQatari riyal13.72EGPTurkish lira1.08EGPChinese yuan7.37EGPGold 246,888.92EGP/gGold 216,027.80EGP/gGold 185,166.69EGP/gSilver110.13EGP/g
NEWS BREAKING
cyber-crime

Malware dev tries to steal Claude users’ secrets, writes npm slop, leaks own GitHub private token

An npm-slop package “mouse5212-super-formatter” targeting Claude users and acting as a stealer reached 676 downloads before being removed from the registry – and after making a major vibe coding blunder. The AI-generated malware leaked its own GitHub private token, thus allowing OX Security researchers to trace the stolen files and analyze the malware before issuing this warning: “We’re going to see more threat actors getting into the game – uploading more sloppy malwares, mostly mimicking APT groups to get a slice of the cake until npm starts automatically blocking malware completely.” According to researchers Moshe Siman Tov Bustan and Nir Zadok, the sloppy code writer created their GitHub account earlier this month, just hours before uploading their first malicious version to npm and shortly after testing out the information-stealing capabilities on a “test” repository. The GitHub account was deleted after the attack. All versions of mouse5212-super-formatter are affected, according to the threat hunters, so if you installed it, immediately revoke your GitHub access tokens and assume any unusual files in the “/mnt/user-data” directory have been compromised. This is the storage directory that Anthropic’s AI coding tool Claude uses to handle file uploads, downloads, and code/data outputs. The script purports to be an internal “archive deployment sync” utility that validates a GitHub repository, captures a “network status” snapshot, and then synchronizes local workspace files with a remote tracking tree. In reality, however, it’s a stealer. “It authenticates to GitHub (using an environment token or a hardcoded fallback), checks whether a target repository exists, creates it if needed, then recursively walks a local directory and uploads every file through the GitHub Contents API,” Bustan and Zadok wrote. It stores the stolen files under random per-run folder names, which allows for multiple stealing sessions, and exfiltrates the sensitive info using base64 encoding. The malware also writes a phony network connection log to make it look like a diagnostic – not theft – tool, and uses “intentionally bland” and/or technical comments and commit messages “to reduce suspicion,” the researchers wrote. It does this instead of using redundant or Russian-language comments that would be a dead giveaway the attacker used AI to write the malicious code. Then again, leaking your own tokens also isn’t super stealthy behavior or best practices when it comes to writing malware. ®

المصدر: The Register

0 Views

أضف تعليقاً

Your email address will not be published. Required fields are marked *