# One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No…

> Source: <https://pub.towardsai.net/one-malicious-payload-hijacked-claude-code-and-codex-unchanged-the-friendly-fire-exploit-has-no-1c40cc3698cf?source=rss----98111c9905da---4>
> Published: 2026-07-22 03:45:33+00:00

Member-only story

# One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No Patch

A security researcher wrote a single attack payload against Claude Sonnet 4.6. Then, without changing one byte, the same payload took over Claude Sonnet 5, Claude Opus 4.8, and OpenAI’s Codex running GPT-5.5.

Every agent you asked to *find* the malware ran it instead.

That’s the finding from “Friendly Fire,” an exploit brief published July 9 by Boyan Milanov and Heidy Khlaaf at the AI Now Institute. It is the most important agent-security result of the month, and unlike a benchmark or a model launch, it doesn’t get fixed next week. The authors are explicit: “This cannot be fixed with a model update, because the models still cannot reliably tell the code they are reading from the instructions they are meant to follow.”

I’ve read the brief and reproduced the shape of the attack conceptually below. If you run a coding agent against any repository you didn’t write — and that is the entire point of coding agents — you need to understand this one.

## The setup: an agent doing exactly its job

The scenario is not exotic. You point Claude Code or Codex at a dependency and type the most reasonable prompt imaginable:
