DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Claude Code Auto Mode Bypassed via Zip Payload at 80% Rate

Forensic Summary

Security researcher Johann Rehberger demonstrated an 80% success-rate prompt injection attack against Claude Code's auto mode, Anthropic's default safety mechanism for its coding agent. The attack tricks the agent into downloading and decompressing a zip archive containing a malicious local module that hijacks Python's import resolution to execute arbitrary code. Critically, auto mode was observed blocking Claude's own remediation commands after detecting the compromise, rendering the safety layer counterproductive.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/claude-code-auto-mode-bypassed-via-zip-payload-at-80-rate/

Top comments (0)