Claude Code can be tricked into a reverse shell by a clean GitHub repo
Mozilla's 0DIN research shows a clean GitHub repo with no malicious code can still trick Claude Code into a reverse shell, by hiding the payload in a DNS TXT record the agent runs as a setup fix.