Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce's API for extended periods, as data was stolen. Huntress later disclosed that its own Salesforce ...