{"repo":"s0ld13rr/claude-code-backdoor","free":true,"listed":false,"github":"https://github.com/s0ld13rr/claude-code-backdoor","clone":"git clone https://github.com/s0ld13rr/claude-code-backdoor.git","description":"Backdooring Claude Code via hooks in settings.json. Authorized use only!","language":"JavaScript","stars":86,"topics":["backdoor","claude-code","initial-access","malware","pentesting","persistence","phishing","redteaming"],"license":null,"category":"security-tools","readme_excerpt":"Claude Code Backdoor (PoC) A Proof of Concept demonstrating how Claude Code (Anthropic's CLI AI agent) hooks can be leveraged for Initial Access and Persistence. ⚠️ Disclaimer This project is for educational and ethical security testing purposes only. Unauthorized access to computer systems is illegal. The author is not responsible for any misuse of this information. 🔍 Overview Similar to the classic VSCode tasks.json backdoor, Claude Code provides a \"Hooks\" mechanism. Hooks allow users to execute automated scripts during specific lifecycle events, such as starting a session or executing a command. From a security perspective, these hooks represent a significant attack surface: - Initial Access: By including a malicious .claude/settings.json in a repository, an attacker can execute code when a developer runs claude inside that folder. - Persistence: By modifying the global /.claude/settings.json, an attacker can ensure their payload runs every time the user interacts with the AI agent. ⚙️ How It Works Claude Code looks for configuration in two places: Local: path/to/project/.claude/settings.json Global: /.claude/settings.json (on macOS/Linux) The following configuration executes a script (script.js) automatically when a Claude session starts: 🚀 Attack Scenarios 1. Supply Chain / Social Engineering An attacker sends a Pull Request or invites a developer to a repository for a \"code review.\" If the developer uses Claude Code to analyze the project, the SessionStart hook trigge","default_branch":null,"files":null,"tree":[],"storefront":"/r/s0ld13rr","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/s0ld13rr/claude-code-backdoor/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}