cd /news/ai-safety/one-malicious-payload-hijacked-claud… · home topics ai-safety article
[ARTICLE · art-67950] src=pub.towardsai.net ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No…

A single attack payload hijacked Claude Code and OpenAI's Codex unchanged, according to an exploit brief published July 9 by Boyan Milanov and Heidy Khlaaf at the AI Now Institute. The 'Friendly Fire' exploit, which the authors say cannot be fixed with a model update, caused every agent asked to find malware to run it instead.

read1 min views1 publishedJul 22, 2026
One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No…
Image: Pub (auto-discovered)

Member-only story

A security researcher wrote a single attack payload against Claude Sonnet 4.6. Then, without changing one byte, the same payload took over Claude Sonnet 5, Claude Opus 4.8, and OpenAI’s Codex running GPT-5.5.

Every agent you asked to find the malware ran it instead.

That’s the finding from “Friendly Fire,” an exploit brief published July 9 by Boyan Milanov and Heidy Khlaaf at the AI Now Institute. It is the most important agent-security result of the month, and unlike a benchmark or a model launch, it doesn’t get fixed next week. The authors are explicit: “This cannot be fixed with a model update, because the models still cannot reliably tell the code they are reading from the instructions they are meant to follow.”

I’ve read the brief and reproduced the shape of the attack conceptually below. If you run a coding agent against any repository you didn’t write — and that is the entire point of coding agents — you need to understand this one.

The setup: an agent doing exactly its job #

The scenario is not exotic. You point Claude Code or Codex at a dependency and type the most reasonable prompt imaginable:

── more in #ai-safety 4 stories · sorted by recency
── more on @boyan milanov 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/one-malicious-payloa…] indexed:0 read:1min 2026-07-22 ·