Security Stop-Press : Webpage Tricks Claude Code Into Running Malicious Code

Written by: Paul |

Security Stop-Press : Webpage Tricks Claude Code Into Running Malicious Code

Security researcher Johann Rehberger tricked Claude Code into running malicious code by asking it to summarise a webpage.

Testing Opus 5 in Auto Mode, he steered Claude towards an archive. It rejected a supplied program but wrote a replacement that unknowingly loaded a malicious Python file.

The payload contacted a controlled server and opened Calculator. Another variant launched a second Claude session that ran commands and wrote files outside the working folder.

Three variants succeeded in 60–80 per cent of attempts across five tests each, results Rehberger described as “not comprehensive”

Rehberger, who publishes his findings on the Embrace The Red blog under the name wunderwuzzi, says Anthropic called the behaviour working as designed. Its guidance acknowledges Auto Mode risks and recommends isolation.

Businesses should isolate coding agents, restrict network access, protect credentials and confidential files, and require human review for sensitive actions.