Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher

Malicious instructions buried in a repository's files can hijack Anthropic's Claude Code agent and open a backdoor on the developer's own machine, no obvious malware required.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher
Share

Key points

  • Indirect prompt injection hidden in repository files can instruct Claude Code to spawn a reverse shell on the developer's machine.
  • No malicious binary is needed; the agent executes the attacker's commands under the developer's own credentials.
  • Any repository carrying a payload works: typosquatted projects, transitive dependencies, shared internal templates.
  • Anthropic had issued no security advisory addressing this attack pattern at publication time.
  • Developers should restrict shell-execution permissions, use isolated environments, and treat untrusted repos as hostile input.

How does the attack actually work?

A developer clones what looks like a clean repository. Claude Code reads the project files as context. Buried in a README, a config stub, or a comment block sits a prompt injection payload telling the model to spawn a reverse shell. The developer never runs a suspicious binary. Claude does it for them.

This isn't a vulnerability in the classical sense. No CVE exists for a model following instructions it was given. The problem is architectural: agentic AI tools that read arbitrary file content and execute system commands inherit the trust level of whatever they read. We've followed Anthropic's security posture across 44 stories in the last 90 days, including the June decision to ship a version of Fable 5 with safety classifiers removed, which now looks more consequential in light of this.

Should you worry about what a reverse shell gives an attacker?

Reverse shells are blunt instruments. Once established, an attacker gets an interactive terminal on the victim machine, operating under the developer's credentials. From there, lateral movement is straightforward: secrets from environment variables, cloud provider tokens sitting in ~/.aws or ~/.config. Blast radius scales with whatever access the developer already has.

The payload needn't announce itself. Injection text is written for the model, not for humans, so a casual code review won't catch it. A typosquatted project, a transitive dependency, a shared internal template: each is a plausible carrier.

What should developers do right now?

Treat any repository from an untrusted source as hostile input, not just hostile code. Check what file types the agent is permitted to read and restrict shell-execution permissions where the tool supports it. Run agentic sessions inside a container or VM with no cloud credentials mounted, and audit environment variables before starting any AI-assisted session on a new codebase.

The FTC's authority over unfair or deceptive practices gives it at least theoretical jurisdiction if AI coding tools marketed to consumers cause foreseeable harm through design choices, though no enforcement action has been filed here.

The honest read on this: the capability gap between a chatbot that leaks a summary and an agent with shell access following injected instructions is enormous, and the security conversation around agentic tools hasn't kept pace with how fast they've shipped.

© 2026 Threat Vectr