AgentsSANDWORM_MODE npm Worm MCP Injection Targets 5 AI Coding ToolsSocket.dev·high signalXBlueskyLinkedInCopy link19 malicious npm packages inject rogue MCP servers into Claude Code, Cursor, Windsurf, Continue, VS Code. Exfiltrates SSH keys, AWS creds, API tokens via prompt injection.SourceSource pageSocket.dev↳ Follow the threadShared entity / Stack layerCline Desktop 0.0.25 lets Claude Code and Codex CLI providers start sessions with no API key, and caps Codex models at real backend budgetsGitHub ReleasesShared entity / Stack layerDeepSeek released V4.1-Flash: a 552B causal encoder-decoder that activates 8B params on prefill and 16B on decodeDeepSeek (Hugging Face model card)Shared entity / Stack layerPattern: git worktrees became table stakes across three agent harnesses in four daysGitHubShared entity / Stack layerClaude Code 2.1.267 adds a hard effort ceiling and a flag that stops reusing the recorded system promptClaude Code changelogShared entity / Stack layertigerless-labs/agent-memory is holding ~130 stars a day with a no-API-key markdown memory runtimeGitHubShared entity / Stack layerA skill whose entire job is stopping coding agents from burying the answer gained 4,650 stars in one dayGitHub TrendingShared entity / Stack layerClaude Code MCP servers configured as `http` never connected if the server only spoke legacy HTTP+SSEGitHubShared entity / Stack layerSandboxAQ's Switch Tops Product Hunt by Making Slack and Teams a Vendor-Neutral Room Instead of an Agent StorefrontSandboxAQ press release (2026-08-26) and Product Hunt leaderboard 2026-09-08; corroborated by PR Newswire and the sandbox-quantum/switch repo