Config Files That Run Code: Supply Chain Security Blindspot
https://safedep.io/config-files-that-run-code/
#HackerNews #supplychainsecurity #configfiles #cybersecurity #codingbestpractices #softwarevulnerabilities

Config Files That Run Code: Supply Chain Security Blindspot
Editor and package-manager config files auto-execute commands when a developer opens a folder or installs dependencies. The Miasma worm wired one dropper into seven of them across Claude Code, Gemini, Cursor, VS Code, npm, Composer, and Bundler. Opening a cloned repo is no longer safe.







