Back to feed
AI in IndustryThe Decoder · June 29, 2026 · 4w ago

Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control

Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control

Security researchers at Mozilla's 0DIN platform have shown how a single compromised GitHub repo can take over a developer's machine the moment an AI coding tool like Claude Code runs its setup. The catch: the malicious code only loads at runtime via a DNS query, invisible in the repo, to scanners, and to the AI agent itself. The article Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control appeared first on The Decoder.

Open original

The Daily Drop

Join 1,000+ people who read this first.

Related stories

Anthropic Resets Rate Limits for All Claude Users

Anthropic has reset both 5-hour and weekly rate limits across all Claude user tiers, effectively giving everyone a fresh quota allocation. This appears to be a system-wide refresh rather than a permanent policy change. Why it matters: - Teams hitting rate caps during high-usage periods (end of sprint, campaign launches) get immediate relief without needing to upgrade or wait for natural reset cycles. - The move suggests Anthropic is actively monitoring capacity constraints and willing to manually intervene when bottlenecks emerge, a positive signal for enterprise reliability. - For developers building agentic workflows or batch processing tools, this confirms rate limits remain a real constraint to design around, not just theoretical guardrails. - Marketing teams running large content generation batches should anticipate similar future resets if infrastructure keeps pace with demand growth. This likely reflects either a capacity expansion or a response to user feedback about quota friction. Watch whether Anthropic announces permanent tier adjustments or keeps using ad-hoc resets.

X / @claudedev · 1w ago