Vulnerabilities in Claude Code plugin marketplace

A security researcher found a way to hijack repository names referenced by Anthropic's official plugin marketplace. A repo-jacking attack is possible if a plugin author deletes or renames their GitHub account, leaving an outdated link in the catalog.
An attacker can register the freed-up name and create a repository with malicious content. Although plugin installation is protected by SHA checks, which prevent execution of compromised code, navigating to the plugin's homepage remains a phishing vector.
Anthropic closed the report as informational, citing that social engineering is outside the bug bounty program. Experts advise treating all third-party plugins as untrusted code.
Related stories
- Agentjacking vulnerability exposes Claude Code and Cursor to hijacking via fake error reports
- The .claude directory creates an attack surface in Claude Code
- Claude Code stores MCP OAuth tokens in plaintext on Linux
- Miasma attack targets AI assistant configurations
- Claude Code 2.1.282 ignores telemetry set by project files
- Two Claude Code sessions ate 32% of a team's bill
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
