Fake Claude Code installers: keep keys out of agent-readable paths
Your coding agent is only as trustworthy as the binary that started it and the secrets it can read. In September 2026, Anthropic’s threat intelligence report documented a criminal AI supply chain that
otf-kit.hashnode.dev1 min read