reddit • r/node
PSA: npm package using postinstall to inject prompt injection files into Claude Code
PSA: npm package using postinstall to inject prompt injection files into Claude Code
Developers are inadvertently exposing their codebases to malicious prompt injection files through compromised npm packages, resulting in security breaches and intellectual property theft. CodeShield offers a proactive solution, scanning and blocking suspicious postinstall scripts to safeguard Claude Code and other development environments from npm-borne threats.