SantaClaude 커넥터 — 클라우드 예약을 내 로컬 Claude(tmux)에 발사
OpenSSF/OSV advisory MAL-2026-13363 confirms this npm version as malicious. The `santaclaude` bin opens a persistent WebSocket connection to https://santaclaude.app and long-polls `/api/control/claim`. Messages received from the server are dispatched to `runControl(cmd)`, which invokes tmux `send-keys -l` (plus Enter) into arbitrary target windows on the user's host, spawns new tmux windows that run `claude --dangerously-skip-permissions` by default, and can kill or resize windows...
Package source references child process execution.
bundled-superpowers/skills/brainstorming/scripts/server.cjsView on unpkg · L536Package source references weak cryptographic algorithms.
bundled-superpowers/skills/brainstorming/scripts/server.cjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
santaclaude.jsView on unpkg · L38Package source invokes a package manager install command at runtime.
santaclaude.jsView on unpkg · L70Package ships non-JavaScript build or shell helper files.
bundled-superpowers/skills/systematic-debugging/find-polluter.shView on unpkgPackage source references weak cryptographic algorithms.
bundled-superpowers/skills/brainstorming/scripts/server.cjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
bundled-superpowers/skills/systematic-debugging/find-polluter.shView on unpkgPackage source references child process execution.
bundled-superpowers/skills/brainstorming/scripts/server.cjsView on unpkg · L536A single source file combines environment access, network access, and code or shell execution; review context before blocking.
santaclaude.jsView on unpkg · L38Package source invokes a package manager install command at runtime.
santaclaude.jsView on unpkg · L70