The Shai-Hulud npm supply chain attack doesn't stop at npm install. It plants hooks in .vscode/tasks.json and .claude/settings.json that fire when you open your project — and --ignore-scripts won't save you.

A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository hooks remained present.

A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.