CVE-2026-47729 Was Found by an AI. This Attack Uses AI to Deliver It. Mozilla 0DIN: A Clean GitHub Repo Can Talk Claude Code Into Opening a Reverse Shell — And No Scanner Will Catch It
Mozilla’s Zero Day Investigative Network (0DIN) demonstrated that a GitHub repository containing zero lines of malicious code can cause Claude Code to open a reverse shell on a developer’s machine. The payload is stored in a DNS TXT record controlled by the attacker — it doesn’t exist in the repository, appears only at runtime, and is invisible to static analysis, secret scanners, human code review, and the AI agent itself. The attack works by chaining three individually legitimate steps into a single malicious composition. Affects Claude Code, Cursor, Gemini CLI, and any agentic coding tool that follows setup flows.
