Claude Desktop turned into a C2 agent via configuration poisoning

Pentera Labs red team researchers achieved remote code execution on a developer machine using Claude Desktop. The entry point was a compromised email account linked to a Claude profile.
The attackers injected a base64-encoded instruction into the Claude personal settings. Because these settings sync across all devices and sessions, the poisoned prompt loaded silently in the background upon app launch. If the victim had Desktop Commander or another MCP connector installed, Claude executed a reverse shell. Otherwise, it displayed a fake error message with a link prompting the user to download a malicious utility.
Anthropic stated that personal settings, skills, and MCP connectors execute code by design and this is not a vulnerability. The researchers recommend running agents in a sandbox and monitoring changes to synced configuration files.
Related stories
- A Claude task jumped to a second person's computer
- SharedRoot: escaping the Claude Cowork sandbox on a Mac
- Claude Cowork sandbox bypass allows root code execution
- Confessor reconstructs what Claude Code actually touched
- Agentjacking vulnerability exposes Claude Code and Cursor to hijacking via fake error reports
- Anthropic will bill again for requests its safeguards block
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
