Researchers warn malicious packages can harvest secrets, weaponize CI systems, and spread across projects while carrying a dormant wipe mechanism.
The San Francisco lab calls out Chinese AI developers for using 'sprawling networks of fraudulent accounts' to extract Claude ...