Fetching from the wire…
Public story · 2026-07-30 · high
Claude Code CLI and Codex CLI 0.142.4 both fell to the same disguised-build-artifact payload, per AI Now Institute's Boyan Milanov and Heidy Khlaaf.
Why now: This demonstration surfaced in coverage dated July 30, when vendors pitch coding agents specifically as vulnerability reviewers, the exact job this exploit hijacks.
AI Now Institute researchers hijacked Claude Code and Codex, planting a hidden binary disguised as a build artifact next to a deceptive README.md. The attack ran mid-review, with the agent asked to scan code for vulnerabilities, per Boyan Milanov and Heidy Khlaaf.
That's the exact job these agents get pitched for: reviewing code nobody's vetted yet. Milanov and Khlaaf turned the reviewer into the execution vector.
The payload ran unmodified against Sonnet 5, Opus 4.8, and GPT-5.5, on both Claude Code CLI and Codex CLI 0.142.4. That's two competing products and three model generations, with zero edits between them.
There's no patch here. Milanov and Khlaaf's fix is behavioral: don't hand untrusted code to an agent that can run commands and reach your keys. Sandboxing is partial, and code inside one can still escape. Their write-up doesn't say whether either vendor has hardened its sandbox since.
I run Claude Code against other people's code in my own projects most weeks, so this lands close. Safety training in three separate model generations, from two competing labs, didn't stop any of it. Sandboxing was supposed to be the backstop. This demo shows it leaking.
Each link below shares sources, entities, or timing with this story.
AI Now Institute published a July 9 proof-of-concept where a coding agent in autonomous or auto-review mode gets tricked into executing a concealed binary, disguised as compiled Go inside the geopy library, after a README note suggests running a "security script" (The Hacker N...
Terminal-Bench 2.1 results (entries dated June 17) put Codex CLI on GPT-5.5 first at 83.4%, Claude Code on Fable 5 second at 83.1%, and Claude Code on Opus 4.8 at 78.9%. The asterisk matters more than the ranking: Fable 5 and Mythos 5 have been export-suspended since June 12,...
$3,054 against $38,370. Same benchmark, better score. Praxist (arXiv 2608.25955, submitted August 26) replaces per-attempt agent memory with a typed evidence graph of findings, plus lane-structured frontiers and agendas, so later attempts inherit validated mechanisms rather th...
Two thirds. Not two thirds of a contrived jailbreak set. Two thirds of realistic malicious issue requests, against the exact three tools most of the people reading this run daily. Ankur Singh, Jinqiu Yang, and Tse-Hsun Chen built IssueTrojanBench across four attack categories...
A pharma company with a market cap in the hundreds of billions is pulling roughly 80% of its ServiceNow and adjacent app workloads onto an internal platform called Concierge, built with Cursor and Claude Code, targeting about $10M in savings. Matterfact's SaaS recap has the de...
A GitHub repo cataloging Claude Code tips doesn't normally warrant a top story. But shanraisshan/claude-code-best-practice at 53.4K stars isn't a tips list anymore. It's the de facto reference for how an entire generation of developers is learning to work with AI coding agents...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.