- Claude Code ran the dangerous command while treating it as routine recovery
- A single fake error message triggered the entire hidden attack chain
- Static scanners and firewalls saw nothing more than normal DNS resolution
Researchers at Mozilla's 0din team have shown how Claude Code can be manipulated into opening a hidden reverse shell on a developer's device.