Fetching from the wire…
Public story · 2026-07-14 · high
It hides a Go binary inside the geopy library and runs on both Claude Code and Codex CLI, with no patch yet.
Why now: AI Now Institute's proof-of-concept came out July 9, and there's still no patch reported as of July 14.
AI Now Institute published a proof-of-concept July 9 that tricks a coding agent into running a hidden binary, per The Hacker News. Anyone running Claude Code CLI or OpenAI Codex CLI in autonomous or auto-review mode is exposed. That's two vendors and four models, Sonnet 4.6, Sonnet 5, Opus 4.8, and GPT-5.5, with no patch available.
The exploit, called Friendly Fire, disguises the payload as compiled Go code inside the geopy library. An agent in autonomous or auto-review mode reads the README's suggestion to run a "security script" and executes it. That's the whole attack: no phishing link, no social engineering beyond one plausible sentence in a text file.
It hits Claude Code CLI versions 2.1.116 through 2.1.199 and OpenAI Codex CLI 0.142.4, with no patch out. AI Now Institute is blunt about why: this isn't a bug in either CLI, it's what autonomous command approval is built to do. If an agent can run a command a README suggests, a hostile repo can suggest a bad one.
The real fix is a human approving every command an autonomous agent runs, which is the exact step these tools exist to remove. I'd bet vendors patch the geopy trick, maybe flagging disguised Go binaries or "security script" language in READMEs, before anyone touches the approval model itself. I'd also watch whether Claude Code or Codex change default auto-approve behavior, versus just detecting this one signature.
Each link below shares sources, entities, or timing with this story.
AI Now Institute criticizes Claude Code / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover AI Now Institute, Claude Code CLI, GPT, Opus; cite the same source (The Hacker News).
AI Now Institute criticizes Codex / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (AI Now Institute criticizes Codex); both cover GPT, July, Sonnet; overlapping topics (agent, codex, sonnet).
AI Now Institute criticizes Claude Code / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover GPT, July, Opus; overlapping topics (agent, claude, code).
AI Now Institute criticizes Claude Code / Shared entities / Shared topic
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover GPT, Opus, There; overlapping topics (agent, claude, code, codex, coding).
AI Now Institute criticizes Claude Code / Shared entities / Same source domain / What happened next / Tension
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover GPT, July, Sonnet; reported by the same outlet (thehackernews.com).
AI Now Institute criticizes Claude Code / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover GPT, Opus; overlapping topics (agent, claude, code, codex, coding).
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover Opus, Sonnet; overlapping topics (agent, claude, code, coding, command).
AI Now Institute criticizes Claude Code / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (AI Now Institute criticizes Claude Code); both cover AI Now Institute, Friendly Fire; overlapping topics (agent, autonomou, claude, code, codex).