This is wild stuff. Latest shai hulud using sketchy prompts to trigger LLM safeguards and thus skip code scanning.
socket.dev/blog/mini-sh...
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.
socket.dev
Brian LeRoux