One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No… A single attack payload hijacked Claude Code and OpenAI's Codex unchanged, according to an exploit brief published July 9 by Boyan Milanov and Heidy Khlaaf at the AI Now Institute. The 'Friendly Fire' exploit, which the authors say cannot be fixed with a model update, caused every agent asked to find malware to run it instead. Member-only story One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No Patch A security researcher wrote a single attack payload against Claude Sonnet 4.6. Then, without changing one byte, the same payload took over Claude Sonnet 5, Claude Opus 4.8, and OpenAI’s Codex running GPT-5.5. Every agent you asked to find the malware ran it instead. That’s the finding from “Friendly Fire,” an exploit brief published July 9 by Boyan Milanov and Heidy Khlaaf at the AI Now Institute. It is the most important agent-security result of the month, and unlike a benchmark or a model launch, it doesn’t get fixed next week. The authors are explicit: “This cannot be fixed with a model update, because the models still cannot reliably tell the code they are reading from the instructions they are meant to follow.” I’ve read the brief and reproduced the shape of the attack conceptually below. If you run a coding agent against any repository you didn’t write — and that is the entire point of coding agents — you need to understand this one. The setup: an agent doing exactly its job The scenario is not exotic. You point Claude Code or Codex at a dependency and type the most reasonable prompt imaginable: