WorkThe story, in brief

Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control

Claude Code just became a malware vector. Mozilla researchers showed how a single GitHub repo can hijack a dev machine—and the AI agent never sees it coming.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI coding agents like Claude Code are now a supply-chain attack surface. As developers delegate repo setup to agents, attackers can use runtime code injection (DNS queries) to bypass both static analysis and AI verification, turning productivity tools into silent entry points.

The key facts

6 to know
  1. Mozilla 0DIN platform identified vulnerability

  2. Attack vector: compromised GitHub repo + Claude Code automation

  3. Malware loads at runtime via DNS query (invisible to scanners and AI)

  4. No static code verification by AI agents

  5. Supply-chain risk via developer tooling

  6. Published June 2026

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: Security researchers at Mozilla's 0DIN platform have shown how a single compromised GitHub repo can take over a developer's machine the moment an AI coding tool like Claude Code runs its setup. The catch: the malicious code only loads at runtime via a DNS query, invisible in the repo, to scanners,…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work