Users could be tricked into running arbitrary code, but the issue was patched last week.
Why can't it just be a basic text editor?!
SmartLoader campaign spreading StealC via a trojanized Oura MCP server using fake GitHub forks to steal credentials and crypto funds.