SlowMist founder flags poisoning risk in Claude Code and Grok Build CLI

SlowMist founder flags poisoning risk in Claude Code and Grok Build CLI

N
News Editor
2026-07-18 02:12:32
Odaily reported that SlowMist founder Yu Xian reposted a warning on X about a potential poisoning attack against Claude Code and published his own analysis covering poisoning risks tied to both Grok Build CLI and Claude Code CLI. According to the analysis, Grok Build CLI lacks a unified security model, with different code paths relying on different trust assumptions. That gap could let attackers use a malicious project configuration file to run arbitrary commands without the user’s knowledge. Researchers also built a test environment and found that on macOS, if Claude Code is affected, running a specific test command could launch the local Calculator app, which they said demonstrates a potential command execution risk. If such an attack succeeds, it could lead to the theft of API keys for AI services such as Claude and OpenAI, cloud credentials for AWS, Alibaba Cloud and Tencent Cloud, unauthorized access to servers and data, code repository tampering, backdoor insertion, and the use of a local machine as a pivot point into an enterprise internal network. The report added that the related vulnerability has existed for one year.
Claude CodeGrok Build CLISlowMistYu Xiancommand executionAPI keyscloud credentialssecurity risk

Odaily reported that SlowMist founder Yu Xian reposted a warning on X about a potential poisoning attack involving Claude Code and then published an analysis of poisoning attack details tied to both Grok Build CLI and Claude Code CLI.

In that analysis, he said Grok Build CLI does not have a unified security mechanism. Different code paths rely on different trust assumptions, and those gaps can become an entry point for attackers. A malicious project configuration file could allow an attacker to execute arbitrary commands without the user’s knowledge, then steal API keys, cloud credentials, or take control of a local device.

Researchers built a test environment and found that on macOS, if Claude Code is affected, running a specific test command can trigger the local Calculator app. They said this shows a potential command execution risk.

If the attack succeeds, an attacker could also steal API keys for AI services including Claude and OpenAI, causing account billing losses. The attacker could also obtain cloud service credentials for AWS, Alibaba Cloud, and Tencent Cloud to access servers and data, tamper with code repositories to plant backdoors, and use the compromised local device as a springboard into an enterprise’s internal network.

The report said the related vulnerability has already existed for one year.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.