Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
A reverse shell makes the target machine initiate the connection back to the attacker, bypassing firewalls that only filter ...