AgentsSANDWORM_MODE npm Worm MCP Injection Targets 5 AI Coding ToolsSocket.dev·high signalXBlueskyLinkedInCopy link19 malicious npm packages inject rogue MCP servers into Claude Code, Cursor, Windsurf, Continue, VS Code. Exfiltrates SSH keys, AWS creds, API tokens via prompt injection.SourceSource pageSocket.dev↳ Follow the threadShared entity / Policy dependencyECC has 243,870 stars and 36,883 forks but has not tagged a release in a month despite pushing dailyGitHubShared entity / Stack layergraphify is tagging a release almost daily, three in five days, at 111,804 starsGitHubShared entity / Stack layerCursor Cloud Agents Drop the GitHub Requirement EntirelyCursor ChangelogShared entity / Stack layertare does quota forensics on Claude Code logs and finds the cost is re-sent context, not new workShow HNShared entity / Stack layerOpenHands v1.16.0 replaces its all-on skill catalog with an explicit allow-listGitHubShared entity / Stack layerGrith Scores Every Syscall a Coding Agent Makes and Queues the Ambiguous Ones for a HumanGitHub (Show HN, 2026-08-28)Shared entity / Stack layerVercel's AI SDK harness layer adds Cursor, making eight coding agents swappable behind one interfaceVercel ChangelogShared entity / Stack layerA Builder Cut a Third Off Their Claude Code Token Burn by Having Apple Intelligence Write Session Handoffs Overnightr/ClaudeAI