Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
"button" data-redirect-url=" data-display-label="0" data-show-count="1" data-bookmark-label="Save" ...
"button" data-redirect-url=" data-display-label="0" data-show-count="1" data-bookmark-label="Save" ...