Skills
Claude Code CVE-2025-59536 / CVE-2026-21852: Project-File Supply Chain Attack Vectors and Mitigations
Check Point Research disclosed that ANTHROPIC_BASE_URL in a repository's .claude config can redirect all Claude API traffic (including full authorization headers) to an attacker-controlled server before the user reads a trust dialog, exfiltrating API keys in plaintext. A second vector abuses Hook automation to execute arbitrary shell commands the instant Claude Code opens an untrusted project. Defense: never open unreviewed repositories in Claude Code; treat .claude/ project files like executable code in your threat model.
↳ Follow the thread