Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    BlueHammer Vulnerability Exploited in Ransomware Attacks

    June 30, 2026

    Tesla and SpaceX Shaping Demand and Supply of 20% of US Energy Grid

    June 30, 2026

    GMKtec EVO-T2 review: An impressive AI mini PC that goes some way to addressing the imbalance between the best Intel can offer over AMD

    June 30, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines
    Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines
    Cybersecurity

    Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines

    The Tech GuyBy The Tech GuyJune 30, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Attackers can take over developers’ systems by hiding indirect prompts in normal-looking repositories that, when executed by Claude Code, cause the agent to spawn a reverse shell, Mozilla’s 0Din security researchers warn.

    Advertisement

    The attack raises no red flags because the attacker’s repository contains no malicious instructions or code, and when the repository is cloned, Claude Code follows legitimate installation steps.

    The repository contains setup notes that Claude Code follows when asked to get the cloned repository running. The entire attack relies on an error thrown during installation and on Claude Code being instructed to fix it.

    During the first-time setup, Claude Code is instructed to use a Python package, but the package throws an error if it has been used before initialization.

    The error message says “Run: python3 -m axiom init”, and Claude Code reads the error and runs the command for recovery.

    Running ‘init’, however, calls setup.sh, a shell script that pulls a config value from a DNS TXT record, and executes it as a command, which results in an interactive shell spawning on the developer’s machine.

    Advertisement. Scroll to continue reading.

    “The DNS value is base64-encoded, so a reverse-shell signature never appears in plaintext anywhere on disk or on the wire,” the researchers explain.

    The attack hides in plain sight: the payload is never hosted in the repository but lives in a DNS TXT record and can be changed at any time, and the developer is never notified of code execution.

    “The reverse shell is three indirection steps away from anything Claude Code actually evaluated: an error message it trusted, a script that fetched a value, and a DNS record it never saw,” the Mozilla researchers note.

    Once the interactive shell is opened, all credentials, API keys, tokens, and other secrets on the machine can be exfiltrated. Furthermore, the attacker can deploy a backdoor for persistent access after the shell is closed.

    According to Mozilla, a threat actor can disseminate the link to their repository via job posts, tutorials, or messages, and the attack hits all users who open the repo with Claude Code.

    “The attack splits its components across three systems that are never examined together: the repository, the DNS infrastructure, and the developer’s trust in their AI agent. Static analysis sees a DNS lookup. Network monitoring sees name resolution. The agent sees a pre-authorised setup step. None of the three looks malicious in isolation,” the Mozilla researchers said.

    Related: OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

    Related: OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI

    Related: Chinese Framework Powers 200,000 Scam Sites

    Related: In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    BlueHammer Vulnerability Exploited in Ransomware Attacks

    June 30, 2026

    Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat

    June 30, 2026

    New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking

    June 30, 2026

    WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy

    June 29, 2026

    ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access

    June 29, 2026

    New Enterprise-Ready MCP Specification Brings New Security Challenges

    June 28, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026169 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202690 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    BlueHammer Vulnerability Exploited in Ransomware Attacks

    June 30, 2026

    Tesla and SpaceX Shaping Demand and Supply of 20% of US Energy Grid

    June 30, 2026

    GMKtec EVO-T2 review: An impressive AI mini PC that goes some way to addressing the imbalance between the best Intel can offer over AMD

    June 30, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.