Tech & AI News
The Next Web

A researcher hijacked Claude Code by asking it to summarise a web page

The researcher showed that Claude Code in Auto Mode can be coerced into executing attacker-supplied code via a crafted web page that triggers a failed WebFetch, causing a fallback curl download of a malicious ZIP. The ZIP contains a Python module that shadows the standard struct library, enabling the model to import attacker-controlled code, spawn a Python process, retrieve a payload, and run arbitrary commands such as opening Calculator or launching a new Claude session. Tests of three variants, each run five times, achieved 60-80% success, leading to a recommendation to sandbox coding agents and avoid trusting model output.