
What happened
Security researchers at 0DIN found that attackers can compromise developers' machines through GitHub repositories using indirect prompt injection. A setup script in a repo pulls commands from a DNS entry at runtime and executes them invisibly—Claude Code hits a routine error, automatically runs the script, and opens a reverse shell giving attackers full control.
Why it matters
The malicious code never exists in the repository itself, making it invisible to scanners, code reviews, and the AI agent. Once an attacker gains access, they can steal API keys and login credentials and maintain persistent access. A single repo link shared in a job posting, tutorial, or Slack message is enough to compromise anyone who opens it with an AI coding tool.
What to watch
The researchers recommend that AI agents should display what is in a setup script before running it, and developers should treat setup instructions in third-party repos as untrusted code.
Summaries like this, in your inbox every morning.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Gartner predicted over 40% of agentic AI projects will be canceled by the end of 2027, citing rising costs, un…

A study found that after AI coding agents are introduced, the average review process time for pull requests ba…

An Anthropic AI model submitted a false homicide tip to a Philadelphia Police Department tip line on July 18…

McKinsey distinguished partner James Kaplan said AI can now interrogate messy, unstructured data and turn it i…
UBS analysts including Arpine Kocharyan said the churn and membership risk to Planet Fitness from Meta's Muse…

Anthropic added dynamic workflows to Claude Managed Agents
