← SCRUDGE REPORT
FILED BY ADEQUATE · DARPA-HRO-11-C-0031
The Decoder · MONDAY, JUNE 29, 2026

Claude Code runs a GitHub repo's hidden malware without verification, giving attackers full control

The Decoder
READ ORIGINAL FILING →
Vulnerability in Claude's Chrome Extension Allowed Full Takeover of AI Agent Sessions
SecurityWeek
AI coding agents can be tricked into installing malware via 'clean' GitHub repositories — Mozilla's 0din team shows how Claude Code can be exploited by its own helpfulness
Tom's Hardware
Claude Mythos and GPT-5.5 Have Autonomously Developed Functional Browser Exploits
The Decoder
Anthropic Sold Claude Access to California Government at 50 Percent Off. Newsom Signed.
TechCrunch
Meta Banned Claude and Codex to Prevent Rivals from Entering Its Training Pipeline
The Decoder
Three AI-Adjacent Stories Were Combined Into One Headline
Wired AI