Crypto Ticker:
sysadmin from Cyber Security News

Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS

Tushar Subhra Dutta
5 hours ago
9 Views
0 Comments
Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS

Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A new Elastic investigation found a session that opened reverse tunnels, sent login details to temporary public addresses, and created LaunchAgent entries that could survive logout or restart. The activity did not look like a conventional malware dropper. Instead, trusted coding-agent processes launched shells and helper tools that published a local application to the internet, then checked whether it remained reachable. That mix makes the incident meaningful for teams already watching how Claude Code security weaknesses can put developer systems at risk. Elastic researchers...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!