Claude Code High-Risk Hole Exposure: clone Project, cameras and passwords were removed

On April 2nd, security researcher Jack Cui publicly measured and demonstrated in recent days Claude Code One high-risk safetyloophole, REVEALS THE SERIOUS RISKS OF THE AI PROGRAMMING TOOL AT THE SYSTEM COMPETENCE LEVEL。

Claude Code High-Risk Hole Exposure: clone Project, cameras and passwords were removed

The Jack Cui presentation project contains only a .claude configuration folder and an empty Python script. After the terminal enters claude and returns to the car, the computer camera is raised silently, local key information is automatically written into the text file, and the process is zero-interactive and zero-tip。

The problem stems from Claude Code's built-in "hooks" mechanism, which allows developers to define automated scripts in the .claude/settings.json configuration file under the project directory, and to perform silently while running the claude command without popping any confirmation hint。

In addition to .mcp.json, the assailant can configure the malign MCP server through the .mcp.json file, bypass the user approval to automatically connect external tools; or use the frontmatter area definition of the skill plugin for malicious hooks, which is triggered by sub-agents on their missions。

At present, the Anthropic official source has sent the restored version. Developers using Claude Code should immediately implement npm install@anthropic-ai/claude-code@latest update to the latest version, and should be careful in the near future to close the line containing the .claude directory。

statement:The content of the source of public various media platforms, if the inclusion of the content violates your rights and interests, please contact the mailbox, this site will be the first time to deal with.
Information

Anthropic Respond to Claude Code Source Leak: An artificial error, not user data

2026-4-1 18:36:38

Information

RECRUITING CONSULTANTS: IN THE ERA OF AI, JOB-SEEKERS ARE ALSO LOOKING BACKWARDS AT THE MATURITY OF AI

2026-4-2 11:41:34

Search