A malicious repo can run attacker code before some AI agents ask for… — The Hacker News — TG.ME

‼️ A malicious repo can run attacker code before some AI agents ask for trust.

Seven agents are affected, including Claude Code, Codex, and Cursor. The repo must arrive as files with .git intact; four were unpatched at publication.

Read how: https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html
September 2, 2026 2K 10