s0ld13rr / claude-code-backdoor
PublicBackdooring Claude Code via hooks in settings.json. Authorized use only!
A proof-of-concept project demonstrating how configuration hooks in an AI coding CLI tool can be abused for unauthorized code execution and persistence.
How It Works
You find a GitHub project sharing a clever security experiment about hidden risks in AI coding helpers.
You learn how sneaky setups in shared projects can make AI tools run extra code without users noticing.
You make a sample project folder with a hidden note that triggers a simple activity logger when the AI starts.
You start your AI assistant in the test folder, and it quietly activates the hidden logger just like in real scenarios.
You check and see a new record file proving the hidden action happened automatically.
Now you understand the trick and know to carefully check projects before using AI tools, keeping everything secure.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.