← All news·2026-06-29·5 min read

A single GitHub Repo can take over your computer with Claude Code

In a bug bounty report called “Clone this repo and I own your machine,” Mozilla’s 0DIN platform revealed how a malicious Github repo can take over a developer’s entire system using Claude Code.

aisecurityclaude-codecybersecuritydevelopers

By tricking a developer into cloning a malicious Github repository, an attacker can gain complete control over their target’s computer using Claude Code. On June 29th, the 0DIN platform — which hosts a bug bounty competition around finding bugs in generative AI tools — published a blog post describing this method of attack.

This attack is designed to slip past defenses. In a malicious Github repository, there’s a setup script that appears completely benign, since the real threat doesn’t exist in the code base. When the script runs, it performs a DNS query and fetches an arbitrary command from a TXT field in the domain’s DNS record. Since the payload exists outside of the code base, it won’t be detected by static analyzers, code review software, or even Claude Code itself while it’s scanning the code.

Why Claude Code executes it without asking

If Claude Code encounters a common error when setting up a repository (which happens often during normal development), it will continue to run the setup script without displaying the full script to the user or asking them to authorize it. In this way, the attacker gets a reverse shell onto the victim’s computer, allowing them to steal API tokens and login information, and even plant long-lived backdoors that persist beyond the lifetime of the terminal session.

Anyone can be affected by this type of attack, so long as they are exposed to code links somewhere in their workflow. This could happen if they’re applying for jobs, following along with tutorials, receiving messages on Slack/Discord, or any other scenario where they might see a Github link. AI code agents that are set to automatically run setup scripts are particularly vulnerable, since they assume the code they encounter is benign by default.

What AI coding tools should do differently

To protect against these kinds of attacks, the 0DIN team suggests that AI code agents should show the entire setup script to users before running it, treating third-party repositories as untrusted. This isn’t an unreasonable expectation — for years, operating systems have been warning users that downloaded executables require permission. Unfortunately, AI code agents have gained shell access too quickly for security practices to keep up. Just like Claude Code can execute commands, access the file system, and run scripts, it also needs to follow a secure model for what commands it executes.

This is an example of a supply chain attack, and it works because there’s no malicious code in the codebase. There’s nothing that a human or AI code reviewer would be able to find, because the malicious instruction only exists at runtime when a DNS request is made. The issue here is that the code is different from the runtime behavior. At the time of publication, Anthropic has not responded about when they plan to address this issue.

ℹWhat I'd actually do

Before Claude Code sets up any unfamiliar repository, open the setup script and read it yourself — it takes thirty seconds. If a repository arrived via a job application, a cold message, or a link you didn't specifically seek out, treat it the way you'd treat an executable downloaded from an unknown website: read it before running it. This one habit is the complete mitigation until AI tools ship a proper fix.

Source: the-decoder.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health