The Workspace Is the New Perimeter: Three Supply-Chain Waves and the Week Your CLAUDE.md Became a Payload
In seven days, one threat actor ran three separate supply-chain waves across npm, GitHub, and Composer, and a fourth campaign started writing hidden instructions into .cursorrules and CLAUDE.md files so your own AI assistant exfiltrates your secrets. The trust boundary moved into the developer workspace, and provenance signing, MCP federal guidance, and the first papal AI encyclical all landed the same week as the response.