shipfeedAI news, curated daily

16:59:18 CET
29 JUN16:59:18shipfeed
pull to refreshlast sync
Just in — 30 new
§ claude-code · storyline

Claude Code runs malware from compromised repos without verification

Anthropic's Claude Code executes malicious code from compromised repositories without verification, enabling full machine takeover via runtime-loaded payloads.

today · · primary fetch1 sourceupdated today ·

Security researchers at Mozilla's 0DIN platform have shown how a single compromised GitHub repo can take over a developer's machine the moment an AI coding tool like Claude Code runs its setup. The catch: the malicious code only loads at runtime via a DNS query, invisible in the repo, to scanners, and to the AI agent itself.

The article Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control appeared first on The Decoder.

read full article on the-decoder.com
§ sources1 publication · timeline below
  1. the-decoder.comClaude Code runs a GitHub repo's hidden malware without verification, giving attackers full controlprimary