npm · Malicious package advisory
Malware@bonsai-ai/claude-code-win32-x64
MAL-2026-4371
Malicious code in @bonsai-ai/claude-code-win32-x64 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d6591be3fe5d0b37196562035353367d96a2bb1390d8f0f4dae3c5abbfd927f6) Package is published under the `@bonsai-ai` scope but impersonates Anthropic's official `@anthropic-ai/claude-code-win32-x64` platform package. `package.json` declares `"name": "@bonsai-ai/claude-code-win32-x64"` with description `"Native binary for Claude Code on win32-x64"`; `LICENSE.md` reads `© Anthropic PBC`; and the README itself directs users to the legitimate `@anthropic-ai/claude-code` package. The tarball's `files` array publishes only `claude.exe` (228,410,016 bytes, sha256 a8610bedd1a60f4d5288e5a8ceab3abc5d12a37cc5ad3e12d6ed29da1f946bfc), `README.md`, and `LICENSE.md` — no source, no build script, no checksum file, no signature reference, and no relationship between the `@bonsai-ai` publisher and Anthropic. A developer who installs this and runs the resulting `claude` CLI executes 228 MB of opaque attacker-controlled bytes with full user privileges. The combination of Anthropic-brand impersonation, unauthorized publisher, and a single unverifiable native executable as the entire payload is a supply-chain attack regardless of whether the binary happens to be bit-identical to Anthropic's release — the publisher has no authority to redistribute it and consumers have no way to verify what they are running.
Compromised versions (1)
- 2.1.141
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.