<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<oembed>
  <author_name>hasekin28</author_name>
  <author_url>https://blog.hatena.ne.jp/hasekin28/</author_url>
  <blog_title>エラー大全集</blog_title>
  <blog_url>https://error-daizenn.hatenablog.com/</blog_url>
  <categories>
  </categories>
  <description>Claude Code パッケージングエラーを悪用したキャンペーンと防御者が取るべき具体策 冒頭文Anthropic の Claude Code に関する npm リリースのパッケージングエラーを悪用し、偽の GitHub リポジトリ経由で Vidar、GhostSocks、PureLog といった資格情報窃取型マルウェアが配布されるキャンペーンが確認された。本稿はインシデントの要点を整理し、被害拡大を抑えるための即時対応、検出手法、恒久的な予防策を実務中心で示す。 概要と発見経緯 観測されたアーティファクト（要旨） 被害の仕組みとリスク評価 即時対応（初動で必ず行うこと） 検出とハンティング…</description>
  <height>190</height>
  <html>&lt;iframe src=&quot;https://hatenablog-parts.com/embed?url=https%3A%2F%2Ferror-daizenn.hatenablog.com%2Fentry%2F2026%2F04%2F09%2F062417&quot; title=&quot;Claude Code パッケージングエラーを悪用したキャンペーンと防御者が取るべき具体策 - エラー大全集&quot; class=&quot;embed-card embed-blogcard&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;&quot;&gt;&lt;/iframe&gt;</html>
  <image_url>https://cdn-ak.f.st-hatena.com/images/fotolife/h/hasekin28/20260409/20260409062406.png</image_url>
  <provider_name>Hatena Blog</provider_name>
  <provider_url>https://hatena.blog</provider_url>
  <published>2026-04-09 06:24:17</published>
  <title>Claude Code パッケージングエラーを悪用したキャンペーンと防御者が取るべき具体策</title>
  <type>rich</type>
  <url>https://error-daizenn.hatenablog.com/entry/2026/04/09/062417</url>
  <version>1.0</version>
  <width>100%</width>
</oembed>
