Menu

Categories

Tags

This npm worm poses as Claude AI to backdoor your code

May 12, 2026 | Source: socket | Anthropic, Developer | 198 views 0 comments

Socket.dev's reverse engineering of the router_init.js worm payload reveals the full attack chain. The 2.3MB obfuscated file masquerades as a TanStack router initialization module. Once installed, it steals high-privilege credentials from GitHub Actions, AWS, Vault, Kubernetes, and other environments — and then tries to infect other packages maintained by the victim.

Step one: poisoning CI. The attacker piggybacks on TanStack's GitHub Actions using pull_request_target, planting malicious code in the dependency cache. When a maintainer triggers a legitimate release, the tainted cache gets restored. The malware then extracts OIDC tokens from the GitHub Actions runner process memory and publishes directly to npm. It never steals long-term npm tokens, but still manages to push poisoned packages with a valid provenance trail.

Step two: infesting developer tools. According to Socket, the worm copies itself to .claude/router_runtime.js, .claude/settings.json, .claude/setup.mjs, .vscode/setup.mjs, and .vscode/tasks.json. Claude Code hooks re-execute the malware on file edit and bash tool events. VS Code task configurations provide another resurrection path. A simple npm uninstall won't cut it.

Step three: spreading by impersonating an AI bot. After grabbing a GitHub token, the worm uses the GitHub GraphQL API to write files into .github/workflows/, .claude/, and .vscode/ directories under the victim's repos. It forges commit authorship as [email protected]. In repos where Claude Code is already integrated, these commits blend right in with legitimate AI agent activity.

Step four: exfiltrating data through Session. Socket says the payload includes a Session decentralized communication protocol stack. Stolen credentials are sent out via filev2.getsession[.]org and the Session service node network. For enterprise security appliances, this traffic looks more like encrypted chat protocol messages than traditional hacker C2 callbacks — making it harder to block by domain or signature.

Leave a Reply

Your email address will not be published. Required fields are marked *