Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control
Security researchers have discovered that the Claude Code AI tool can be manipulated to execute hidden malware embedded within a GitHub repository. Because the malicious payload is triggered via a runtime DNS query rather than static files, it evades standard repository security scans. This vulnerability allows attackers to gain unauthorized access to a developer's machine as soon as the tool initializes. The finding highlights a significant security risk for developers using AI agents that automatically interpret and execute code from external sources.
Covered by 1 source
- TThe Decoder↗Matthias BastianJun 29