Malicious code in @bonsai-ai/claude-code-win32-x64 (npm)
-= Per source details. Do not edit below this line.=-
Package is published under the @bonsai-ai scope but impersonates Anthropic's official @anthropic-ai/claude-code-win32-x64 platform package. package.json declares "name": "@bonsai-ai/claude-code-win32-x64" with description "Native binary for Claude Code on win32-x64"; LICENSE.md reads © Anthropic PBC; and the README itself directs users to the legitimate @anthropic-ai/claude-code package. The tarball's files array publishes only claude.exe (228,410,016 bytes, sha256 a8610bedd1a60f4d5288e5a8ceab3abc5d12a37cc5ad3e12d6ed29da1f946bfc), README.md, and LICENSE.md — no source, no build script, no checksum file, no signature reference, and no relationship between the @bonsai-ai publisher and Anthropic. A developer who installs this and runs the resulting claude CLI executes 228 MB of opaque attacker-controlled bytes with full user privileges. The combination of Anthropic-brand impersonation, unauthorized publisher, and a single unverifiable native executable as the entire payload is a supply-chain attack regardless of whether the binary happens to be bit-identical to Anthropic's release — the publisher has no authority to redistribute it and consumers have no way to verify what they are running.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준