Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Claude Code Flaws Exposed Developer Devices to Silent Hacking

Anthropic has patched vulnerabilities whose impact was demonstrated by Check Point via malicious configuration files.

Claude

Check Point researchers discovered serious vulnerabilities in Anthropic’s Claude Code tool that could have allowed attackers to silently gain control of a developer’s computer.

The security firm began analyzing the AI-powered coding assistant Claude Code last year, finding ways to abuse its capabilities for malicious purposes using specially crafted configuration files. 

Anthropic has since implemented patches and mitigations for the vulnerabilities. 

Claude Code configuration files enable the customization of model preferences, tool integrations, permissions, and automated hooks to streamline development workflows and ensure consistent team behavior. 

These configuration files can be modified by anyone who has access to the repository and they are automatically copied when a repository is cloned.

The hooks defined in these configuration files control the execution of user commands at specified points. Check Point researchers discovered that an attacker can add hooks that trigger the execution of arbitrary commands on developers’ devices.

Advertisement. Scroll to continue reading.

While Claude requested explicit approval from the user to execute other files within a project, it did not request permission to run hook commands, automatically running them when the project was initialized.

The researchers also looked at MCP integrations designed to enable the use of additional services when a project is opened. They found that configuration settings could be used to override user approval for external actions, thus bypassing consent mechanisms.

The third major issue identified by Check Point experts is related to the API key used by Claude Code to communicate with Anthropic services. Manipulating the configuration settings could have allowed an attacker to redirect API traffic to the attacker’s server, enabling them to exfiltrate API keys and capture credentials.

“Unlike the code execution vulnerabilities that compromised a single developer’s machine, a stolen API key may provide access to an entire team’s shared resources,” Check Point warned.

[ Read: New AI Vulnerability Scanner Sends Cybersecurity Shares Plunging ]

An attacker could have abused these configuration files by getting the targeted user to clone and load a malicious code repository. Attacks could also have been conducted by malicious insiders or via malicious pull requests submitted to the targeted project. 

The vulnerabilities were reported to Anthropic over several months, from July to October 2025, and the AI firm rolled out fixes shortly after each report.

The vendor has implemented additional warnings and user confirmation for potentially dangerous actions. 

Related: Autonomous AI Agents Provide New Class of Supply Chain Attack

Related: Vibe Coding Tested: AI Agents Nail SQLi but Fail Miserably on Security Controls

Related: Anthropic Says Claude AI Powered 90% of Chinese Espionage Campaign

Related: Claude AI APIs Can Be Abused for Data Exfiltration

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.