
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
cc-channel-patch
Advanced tools
One-command patch to enable Claude Code Channels (bypasses tengu_harbor feature flag)
一键启用 Claude Code Channels 功能。
适用于使用代理认证(非 claude.ai 直接登录)的用户,绕过 Anthropic 的 tengu_harbor 云控开关和 accessToken 检查。
# 修补(启用 Channels)
npx cc-channel-patch
# 恢复原始版本
npx cc-channel-patch unpatch
Claude Code v2.1.80+ 内置了 Channels 功能(通过 MCP Server 桥接外部消息平台),但受服务端 feature flag 灰度控制。此补丁修改 3 处检查:
PaH() — tengu_harbor feature flag 始终返回 trueS1_ gate — 跳过 accessToken 认证检查xl1() UI — 跳过 UI 层的 noAuth 提示补丁按特征字符串搜索(非硬编码偏移量),CC 小版本更新后通常仍可用。
.patched 文件并提示手动替换.baknpx cc-channel-patch unpatch 可随时恢复MIT
FAQs
One-command patch to enable Claude Code Channels (bypasses tengu_harbor feature flag)
The npm package cc-channel-patch receives a total of 17 weekly downloads. As such, cc-channel-patch popularity was classified as not popular.
We found that cc-channel-patch demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.