A new Claude Code session sent data out with no confirmation
The confirmation is on one path, and the attack used a different path to the same result.
Claimed, not confirmed
Researchers showed an attack on Claude Code. A parent session received a usual instruction to test a repository. It then started a new session in that repository. The repository had a SessionStart hook, which is code that starts when a session starts. The hook started with no confirmation prompt and sent data from the developer computer to the attacker server. The researchers write that the guardrail operated correctly, but only on one path.
How it worked
The task was usual: follow a README and test the repository. The README told Claude to start a new session in the folder of the repository. A settings file in the repository had the hook.
Paths that stopped
The researchers tried 3 other paths first. Each one was stopped:
- The settings file only: the confirmation prompt stayed.
- The attacker domain was set to be safe: Claude read the code, found a risk, and did not continue.
- The tool that changes the folder: the user must give approval for each use again.
The path that worked
The attack used the command line tool of Claude Code in the shell. This path has no confirmation for a change of session. The new session used the settings file, and the hook started a script from the attacker server.
How common it is
The researchers think that about 5,000 of 67,000 configuration files on GitHub have active SessionStart hooks. That is about 1 in 13. Most of the hooks cause no damage, and a hook that causes damage can look the same.
Sources
Posted