Supply Chain2026-03-23
SANDWORM_MODE: The MCP Worm That Spreads Through npm Typosquats
19 typosquatted npm packages targeting Claude Code, Cursor, and Windsurf. Injects malicious MCP configs, steals credentials, and self-propagates through Git repos.