A popular NPM package got compromised, attackers updated it to run a post-install script that steals secrets
But the script is a *prompt* run by the user's installation of Claude Code. This avoids it being detected by tools that analyze code for malware
You just got vibepwned
The US government banning Juul, an American company, so less-regulated Chinese cos Guangdong Qisitech (Geek Bar) and Shenzhen iMiracle (Elf Bar) could own the nicotine market was so incredibly stupid.
When you make a Bank ACH transaction, it’s literally just an SFTP upload.
Sent as a NACHA file, it's 940 bytes of ASCII text.
Bank-to-Bank transactions cost ~0.2 cents. As long as it travels via encrypted tunnel; it’s compliant!
Here’s how the quirky system works: