AnalysisCybersecurityJune 29, 2026

Mozilla researchers demonstrate Claude Code attack via hidden prompts

Attackers can hijack developer machines by embedding indirect prompts in repositories that cause Claude Code to spawn a reverse shell. The payload is stored in a DNS TXT record, never appearing in the repository itself.

1 source

More stories today

Open the live feed