
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
Claude Code has features gated behind feature flags and gradual rollouts. CC-Black unlocks them.
┌─────────────────────────────────────────────────────────────┐
│ │
│ 🔒 Teammate Tool → 🔓 UNLOCKED │
│ 🔒 Session Memory → 🔜 COMING SOON │
│ 🔒 Custom Keybindings → 🔜 COMING SOON │
│ │
└─────────────────────────────────────────────────────────────┘
⚠️ Warning: Swarm mode spawns parallel agents that will consume tokens faster. Use wisely.
# Enable swarm mode (Teammate tool)
npx cc-black enable swarm
# Run Claude with hacks enabled
cc
That's it. The cc command runs Claude Code with all your enabled hacks.
| Hack | Status | Description |
|---|---|---|
| swarm | ✅ Available | Teammate tool for parallel agents |
| memory | 🔜 Coming | Persistent memory across sessions |
| keybinds | 🔜 Coming | Custom keyboard shortcuts |
Enables the Teammate tool - spawn parallel Claude instances that work together.
npx cc-black enable swarm
Then in Claude:
"Spawn a team of 3 agents to analyze this codebase"
⚡ Heads up: Multiple agents = multiple token streams. Great for speed, watch your usage.
npx cc-black enable <hack> # Enable a hack
npx cc-black disable <hack> # Disable a hack
npx cc-black list # List available hacks
npx cc-black status # Show what's enabled
npx cc-black update # Re-patch after Claude updates
npx cc-black uninstall # Remove everything
cc # Run Claude with all enabled hacks
~/.cc-black/
├── config.json # Your enabled hacks
├── cli.js # Patched Claude Code
└── bin/
└── cc # Command to run it
Claude Code uses Statsig for feature flags. We patch the local CLI to bypass:
// Before (checks remote flag + subscription)
isEnabled() {
return D8() && OP1(); // Feature flag && subscription check
}
// After (always enabled)
function D8() { return true; }
function OP1() { return true; }
claude commandIf Claude Code updates and things break:
npx cc-black update
This re-copies the CLI and re-applies your enabled hacks.
npx cc-black uninstall
Or manually:
rm -rf ~/.cc-black
# Remove the cc-black line from ~/.zshrc
cc instead of claude?We don't modify your original claude command. The cc command runs the patched version, so you can always use vanilla claude if needed.
Yes! CC-Black finds your Claude Code installation (npm or native) and patches a copy.
Found another hidden feature? PRs welcome!
hacks/
├── swarm.js # Teammate tool
├── memory.js # Session memory (TODO)
└── your-hack.js # Add yours!
MIT
Built with Claude Code by @numman-ali
Not affiliated with Anthropic.
FAQs
Unlock hidden features in Claude Code
We found that cc-black demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.