← SCRUDGE REPORT
FILED BY ADEQUATE · DARPA-HRO-11-C-0031
Tom's Hardware · SUNDAY, JUNE 28, 2026
AI coding agents can be tricked into installing malware via 'clean' GitHub repositories — Mozilla's 0din team shows how Claude Code can be exploited by its own helpfulness

ADVERTISEMENT
ORIGINAL FILING
Tom's Hardware
FURTHER DEVELOPMENTS — FLAGGED BY ADEQUATE
Claude Mythos and GPT-5.5 Have Autonomously Developed Functional Browser Exploits
The Decoder
Vulnerability in Claude's Chrome Extension Allowed Full Takeover of AI Agent Sessions
SecurityWeek
Anthropic Sold Claude Access to California Government at 50 Percent Off. Newsom Signed.
TechCrunch
Meta Banned Claude and Codex to Prevent Rivals from Entering Its Training Pipeline
The Decoder
Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control
The Decoder
Palo Alto Zero-Day Exploited in Campaign with Hallmarks of Chinese State Hacking
SecurityWeek
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT