Mozilla researchers revealed a new attack that tricks Claude Code into running hidden commands from seemingly harmless GitHub repositories.
"I'm afraid there might be snake eggs or babies." ...