Get the latest tech news

Config Files That Run Code: Supply Chain Security Blindspot


Editor and package-manager config files auto-execute commands when a developer opens a folder or installs dependencies. The Miasma worm wired one dropper into seven of them across Claude Code, Gemini, Cursor, VS Code, npm, Composer, and Bundler. Opening a cloned repo is no longer safe.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Code

Code

Photo of supply

supply

Photo of config

config

Related news:

News photo

Wired found code for an unreleased facial recognition feature in Meta's AI app

News photo

3D-printed book turns its own G-code into raised lettering

News photo

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft's Disclosure Process