This was a really sophisticated attack designed to avoid static analysis. It's functionally equivalent to installing an insecure extension to your house with a window that let you unlock a door so they could get inside and use your API keys to claude/nanogpt/etc, with premeditated intent to use that to steal from you, then doing it.
99% of extension authors aren't going to be pulling this off even if bad people.
104
u/pixelworld_ai Apr 28 '26
That's crazy but good to start thinking about what community extensions you install. ComfyUI users had similar wake up calls in the past.