Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
CVE-2026-42208 exploited within 36 hours of disclosure, exposing LiteLLM credentials, risking cloud account compromise.
Sometimes smaller is better.