Claude Code Has Potential Poisoning Attack Risk: Malicious Configuration Files Could Enable Silent Code Execution
SlowMist founder Cosine retweeted a post about the potential poisoning attack risks of Claude Code, pointing out that attackers could execute arbitrary commands without the user's knowledge through malicious project configuration files, thereby stealing API keys, cloud credentials, or controlling local devices. Researchers constructed a test environment and found that in Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks. If the attack succeeds, attackers may further steal API Keys for AI services such as Claude and OpenAI, causing account fee losses; obtain cloud service credentials for AWS, Alibaba Cloud, Tencent Cloud, etc., to access servers and data; tamper with code repositories to implant backdoors; and use local devices as a springboard to attack enterprise internal networks.