TECH NEWS
Researchers Demo New Attack Abusing Claude Code and Harmless-Looking Repositories to Hijack Developer Machines
Attackers can take over developers’ systems by hiding indirect prompts in normal-looking repositories that, when executed by Claude Code, cause the agent to spawn a reverse shell, Mozilla’s 0Din security researchers warn. The attack raises no red flags because the attacker’s repository contains no malicious instructions or code,