Best AI News โ€” Updated Every 3 Hours
Story Page
← All Stories
Home Industry & Money Story
Industry & Money

Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control

Via The Decoder
Monday, Jun 29, 2026 ยท 10:04AM
Summary

Security researchers at Mozilla's 0DIN platform have shown how a single compromised GitHub repo can take over a developer's machine the moment an AI coding tool like Claude Code runs its setup. The catch: the malicious code only loads at runtime via a DNS query, invisible in the repo, to scanners, a

Continue reading the full article
Read at The Decoder
the-decoder.com
Back to all stories