Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
ID: 5a0e0cc6-6715-502f-9aa4-1470fd31004c
STIX ID: report--5a0e0cc6-6715-502f-9aa4-1470fd31004c
Feed Name: The Register (Security)
Threat Score
A security researcher demonstrated a prompt‑injection attack against Anthropic’s Claude Code (Opus 5 Auto Mode) that tricks the agent into downloading a malicious ZIP, uses Python module shadowing to run a poisoned struct.py, and achieves remote code execution (including C2 callback and spawning nested Claude agents); the author recommends sandboxing coding agents and not trusting model outputs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
