News

Security Alert: Claude Code was exposed to have a security backdoor, and the official has launched emergency repairs. Recently, the Ministry of Industry and Information Technology’s Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) issued an important security risk reminder, pointing to the AI ​​tool currently widely used in the programming community - Claude Code

2 min read
Security Alert: Claude Code was exposed to have a security backdoor, and the official has launched emergency repairs. Recently, the Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) of the Ministry of Industry and Information Technology issued an important security risk reminder, pointing to the AI ​​tool currently widely used in the programming community - Claude Code. It is reported that the tool was found to have an undisclosed “security backdoor” built into it, posing a risk of leaking sensitive user information. According to monitoring results, the affected software versions are 2.1.91 to 2.1.196. These versions can automatically transmit sensitive data including the user's geographical location, identity, etc. to the remote server without the user's authorization. In this regard, NVDB recommends that developers and enterprise users immediately check the version number they are currently using. If they are in the above affected range, be sure to uninstall or update to the latest safe version as soon as possible. At the same time, relevant units should strengthen the control of external access rights in the development environment and strengthen traffic monitoring to prevent data violations from being transmitted outside. The controversy began at the end of June this year, when a developer was reverse-analyzing version 2.1.196 of Claude Code and accidentally discovered that starting from version 2.1.91 released on April 2, a covert detection mechanism had been implanted in the tool. This mechanism will check the system time zone and proxy server information in real time to identify Chinese users. It is worth noting that this mechanism has never been disclosed in the previous update logs of the software. In response to public doubts, Anthropic team member Thariq Shihipar responded on social platforms that this is an "experimental" measure, originally intended to prevent account resale and model distillation attacks. Officials said a new version was released on July 2 and the detection feature was removed. This safety hazard triggered a chain reaction in the industry. It is reported that domestic technology giant Alibaba has issued an internal ban, banning employees from using Claude Code in the office environment starting from July 10, and including the tool on the list of high-risk software. For developers who still need to use this tool, paying close attention to official version updates and timely remediation has become the top priority to ensure the security of the development environment. via AI News (author: AI Base)