News
The Ministry of Industry and Information Technology has set the tone for the first time: Claude Code is seriously harmful!
2 min read
Source: zhidx.com
Compiled by Zhidongzhi | Edited by Chen Jia | Yunpeng Zhidongxi reported on July 8 that today, the Ministry of Industry and Information Technology's Network Security Threat and Vulnerability Information Sharing Platform (NVDB) issued an announcement. Its recent monitoring found that the AI programming tool Claude Code owned by the American AI large model company Anthropic has security backdoor risks. The tool has a built-in monitoring mechanism that can send data to remote servers without the user's consent. Return sensitive information such as user region and identity. The Ministry of Industry and Information Technology recommends uninstalling the affected versions immediately. ▲Announcement issued by NVDB of the Ministry of Industry and Information Technology (Source: Network Security Threat and Vulnerability Information Sharing Platform NVDB) From the version line, the affected scope covers Claude Code 2.1.91 to 2.1.196. The official change log of Anthropic shows that 2.1.91 was released on April 2, 2026, and 2.1.196 was released on June 29. As of July 8, the latest version of Claude Code has been updated to 2.1.204. The handling suggestions given by the Ministry of Industry and Information Technology include two levels: first, conduct a comprehensive inspection of the development terminal to confirm whether versions 2.1.91 to 2.1.196 are installed, and immediately uninstall or upgrade to the latest safe version that has cleared the relevant backdoor code; second, strengthen the external permission control and traffic monitoring of development tools in the core business network segment to prevent the illegal transmission of sensitive data. According to the official Anthropic documentation, Claude Code can read the code library, edit files, run commands, and access development environments such as terminals, IDEs, desktops, and browsers. Compared with ordinary chatbots, this type of tool is closer to enterprise code, credentials and intranet development environment, and outreach and data return behaviors are more likely to hit security red lines. Before being prompted by the Ministry of Industry and Information Technology, Claude Code had caused controversy among developers due to its "hidden detection mechanism". On June 30, according to users in the overseas social platform Reddit community, Claude Code has a hidden Trojan built in: it will read the user’s system