VentureBeat AI

Anthropic-scanner mist malware in testbestanden van Skills

Back to overview
AISummary generated by AI from the original source

Anthropic's security scanner missed malicious code hidden in a test file, which executes with full system access during npm test runs. Researcher Jeevan Jutla found that JavaScript testing frameworks automatically discover and run .test.ts files without security inspection, allowing attackers to steal credentials and environment variables from CI pipelines.