logo

Git identity spoof fools Claude into giving bad code the nod

ID: 7942ec83-6cd7-51f9-846d-70b95e53a168

STIX ID: report--7942ec83-6cd7-51f9-846d-70b95e53a168

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-04-16

Date Updated: 2026-04-26

Author: Carly Page

...
...

Manifold Security demonstrated that an AI-driven code review system built on Anthropic's Claude can be tricked into auto-approving malicious commits by simply spoofing Git author name and email; automated workflows that grant trust based on commit metadata or perceived maintainer identity can be bypassed, creating a risk of supply-chain or repository poisoning unless additional controls (e.g., commit signing, independent checks) are enforced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.