← 목록

Opening a cloned repo is no longer safe

reddit_programming 2026-06-08 원문 보기 ↗


Solid breakdown of the Miasma worm — one commit, same dropper wired into 7 config files across VS Code, Claude Code, Gemini, Cursor, npm, Composer, and Bundler. No malicious dep needed, just clone + open.

Nobody reviews these files in PRs.

https://safedep.io/config-files-that-run-code/

Anyone actually treating dotfile diffs as code?

submitted by /u/No_Plan_3442
[link] [comments]