BotBeat
...
← Back

> ▌

AnthropicAnthropic
RESEARCHAnthropic2026-06-01

Security Researchers Demonstrate C2-Like Attacks Using Anthropic's Claude Code Background Agents

Key Takeaways

  • ▸Claude Code's background sessions create a new security boundary that traditional security tools may not detect or monitor
  • ▸The supervisor daemon runs independently of user terminals, enabling persistence even after shell termination
  • ▸Attackers with initial local access could use Markdown and JSON files to establish long-lived C2-like agents
Source:
Hacker Newshttps://www.originhq.com/research/background-c2-agent↗

Summary

Security researchers have identified significant security vulnerabilities in Anthropic's Claude Code, demonstrating how attackers could exploit background AI agents to create persistent command-and-control-like infrastructure. The vulnerability leverages Claude Code's powerful features—including code execution, file access, and persistent background sessions—to establish mostly invisible, persistent agents after initial local code execution. The issue stems from the "supervisor process" architecture introduced in Claude Code v2.1.139, which manages background sessions independently of the terminal that spawned them, creating a security boundary problem that developers and security teams need to understand.

The research, conducted by Lucas Luitjes and Mitchell Turner, details how the supervisor process works as an undocumented local control plane. Through reverse engineering of the daemon process using Ghidra, they mapped the IPC communication channels (named pipes on Windows, Unix domain sockets on Linux/macOS) that the Claude CLI uses to manage background worker processes. The attack vector requires initial local code execution but then enables persistent, long-running agents that survive terminal closure, SSH disconnection, and shell restarts—making detection and remediation significantly more difficult than traditional persistence mechanisms.

  • The vulnerability underscores the challenges security teams face with powerful agentic tools operating at the system level

Editorial Opinion

This research highlights a critical gap in security awareness around modern agentic development tools. While Claude Code's persistent background sessions are powerful for legitimate developer workflows, Anthropic and security teams must establish clearer threat models and detection mechanisms for these new attack surfaces. The ability to maintain persistent agents through undocumented supervisor processes raises important questions about security-by-design principles for AI tools operating at system level. Developers should be aware of these risks in shared or untrusted environments, and Anthropic should consider providing built-in security auditing and hardening options for background sessions.

AI AgentsMLOps & InfrastructureCybersecurityAI Safety & Alignment

More from Anthropic

AnthropicAnthropic
RESEARCH

Anthropic Publishes Guide to Using Claude for Enterprise Vulnerability Discovery

2026-06-01
AnthropicAnthropic
INDUSTRY REPORT

The Agentic Mesh: Rethinking How AI Agents Should Scale Into Business Systems

2026-05-31
AnthropicAnthropic
INDUSTRY REPORT

Claude Code Opus 4.5 Unleashes Practical AI Agents—and Raises Safety Questions

2026-05-31

Comments

Suggested

MinimaxMinimax
PRODUCT LAUNCH

MiniMax Debuts M3: Flagship AI Model for Complex Coding Tasks

2026-06-01
MicrosoftMicrosoft
UPDATE

GitHub Copilot Usage Metrics API Now Tracks AI Adoption Cohorts

2026-06-01
NVIDIANVIDIA
PRODUCT LAUNCH

Nvidia Challenges Apple Silicon with New RTX Spark PC Chip

2026-06-01
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us