Your Agent Config Is Executable Code
ChainDrop used npm lifecycle scripts to steal credentials and spread, then planted Claude Code and VS Code configuration as secondary execution paths. Those files belong in the executable supply-chain surface.
notebook / tag
3 entries with this tag.
ChainDrop used npm lifecycle scripts to steal credentials and spread, then planted Claude Code and VS Code configuration as secondary execution paths. Those files belong in the executable supply-chain surface.
Five models produced the same 127 package-name candidates. Registry review narrowed them to 53 registrable slopsquatting targets, turning model hallucinations into a supply-chain watchlist.
CrowdStrike found viable detection signals for nine of fourteen SANDWORM_MODE behaviors, but only two were reliable enough to alert. The result shows where behavioral detection weakens and where provenance still helps.