TrapDoor supply chain attack poisons CLAUDE.md and .cursorrules files to hijack Claude Code and Cursor agents
The attack steals developer wallets, SSH keys, and credentials.
——0——
QUOTE POST
#1674xlr8harder@XLR8HARDER
All this credential stealing stuff is sort of making me want to make a key-holding VPS that i proxy requests through and block to my dev machine IP.
5:44 PM · May 24, 2026 · 796 Views
like fundamentally the same problem as "my agent might get prompt injected so don't trust it with the keys" except it's all of open source
All this credential stealing stuff is sort of making me want to make a key-holding VPS that i proxy requests through and block to my dev machine IP.
5:44 PM · May 24, 2026 · 796 Views
5:45 PM · May 24, 2026 · 187 Views