MarketsSANDWORM_MODE npm Worm Injects Malicious MCP Servers Into AI Coding ToolsSocket.dev·high signalXBlueskyLinkedInCopy linkMulti-stage npm worm deploys rogue MCP servers into Claude Code Cursor Windsurf configs. 19 typosquatted packages harvest tokens SSH keys cloud creds. Dormant dead switch can wipe home directories.SourceSource pageSocket.dev↳ Follow the threadShared entity / Stack layerCline Desktop 0.0.25 lets Claude Code and Codex CLI providers start sessions with no API key, and caps Codex models at real backend budgetsGitHub ReleasesShared entity / Stack layerDeepSeek released V4.1-Flash: a 552B causal encoder-decoder that activates 8B params on prefill and 16B on decodeDeepSeek (Hugging Face model card)Shared entity / Stack layerPattern: git worktrees became table stakes across three agent harnesses in four daysGitHubShared entity / Stack layerClaude Code 2.1.267 adds a hard effort ceiling and a flag that stops reusing the recorded system promptClaude Code changelogShared entity / Stack layertigerless-labs/agent-memory is holding ~130 stars a day with a no-API-key markdown memory runtimeGitHubShared entity / Stack layerA skill whose entire job is stopping coding agents from burying the answer gained 4,650 stars in one dayGitHub TrendingShared entity / Stack layerSandboxAQ's Switch Tops Product Hunt by Making Slack and Teams a Vendor-Neutral Room Instead of an Agent StorefrontSandboxAQ press release (2026-08-26) and Product Hunt leaderboard 2026-09-08; corroborated by PR Newswire and the sandbox-quantum/switch repoShared entity / Stack layerClaude Code MCP servers configured as `http` never connected if the server only spoke legacy HTTP+SSEGitHub