An npm slop package “mouse5212 super formatter” targeting Claude users and acting as a stealer reached 676 downloads before being removed from the registry and after making a major vibe coding blunder. The AI generated malware leaked its own GitHub private token, thus allowing OX Security researchers to trace the stolen files and analyze the malware before issuing this warning : “Were going to see more threat actors getting into the game – uploading more sloppy malwares, mostly mimicking APT...