[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5Cw1pulVoFT1QTYPEpXuAwpQkvPIPfzDrsr-H979PP4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"09cf6855-f42c-4dfb-83f4-432588b2c881","hidden-prompts-in-repos-hijack-developer-machines-via-claude-code","dd4c09b2-da87-468a-a090-930f66df5e76","Hidden Prompts in Repos Hijack Developer Machines via Claude Code","This attack exploits the implicit trust that AI coding assistants like Claude Code place in repository content, error messages, and setup scripts — all of which can be weaponized with hidden prompt injection payloads. Attackers embed instructions in seemingly legitimate repositories that coerce the AI agent into executing malicious commands, including fetching reverse shell payloads encoded in DNS TXT records. Because developers often grant AI coding tools broad system permissions, a successful compromise yields full access to credentials, API keys, and tokens. This matters because the attack surface is the developer's own machine and trust model, not a traditional vulnerability, making it invisible to most conventional defenses.","**Immediate actions:**\n- Audit and restrict the file system and network permissions granted to AI coding assistants like Claude Code to the principle of least privilege.\n- Treat all third-party repositories as untrusted inputs and sandbox their execution environments before running any setup scripts.\n- Scan DNS TXT records and outbound DNS queries from developer workstations for anomalous base64-encoded or unusually long payloads.\n\n**Long-term improvements:**\n- Establish a vetting and allowlist policy for repositories that AI coding agents are permitted to interact with autonomously.\n- Integrate prompt injection awareness into developer security training so engineers recognize AI agent manipulation as a real threat vector.\n- Enforce endpoint detection and response (EDR) rules that alert on reverse shell spawning from AI assistant processes.\n\n**Detection measures:**\n- Monitor for unexpected outbound connections or shell process creation originating from AI coding tool processes on developer machines.\n- Implement network egress filtering to block unauthorized DNS lookups and connections to unknown external endpoints from developer workstations.\n- Log all commands and scripts executed by AI coding agents to a tamper-evident, centralized log for post-incident review.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-218 SSDF PW.1: Define Security Requirements for Software Development","OWASP Top 10 LLM: LLM01 - Prompt Injection","NIST AI RMF: GOVERN 1.1 - Policies for AI Risk Management","GDPR Article 32: Security of Processing (where developer credential exposure involves personal data)","published","2026-06-29T16:20:54.975098+00:00","2026-06-29T16:20:54.618+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.securityweek.com\u002Fnew-attack-abuses-claude-code-and-harmless-looking-repositories-to-hijack-developer-machines\u002F","researchers-demo-new-claude-code-attack-using-harmless-looking-repositories-to-h-475171","Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"3c46885e-3096-42a1-a7a3-b0e1a8425db5","2026-06-30","morning","ThreatNoir Morning Brief — June 30","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-30\u002Fthreatnoir-morning-brief-2026-06-30.mp3"]