How I Built an 80-Line Python Scanner to Catch Claude Code MCP Hijacking Attacks Before npm Install (opens in new tab)
One `npm install`. That is all it takes for an attacker’s proxy to intercept your MCP traffic, rewrite `~/.claude.json`, and drain your…
Read the original article