I'm quite surprised that we are not seeing something like this more in the wild. Quite concerning
Usually auto mode does mild things that are dismaying but not dangerous, or maybe not noticed (like if it posts sensitive local data in a request that gets logged but never exploited.)
Maybe it is used in the wild, but we just don't know.
It's not that far off a typical trojan, just one tailored to Claude's habits. A lot of the same limits apply.
What vibe "don't even gotta read it" coder would even notice if it happened?