2026-07-11NOTABLEAI Now Institute PoC turns an untrusted library's own files into RCE when Claude Code or Codex CLI review it in auto-mode, no hooks or config needed
Friendly Fire (AI Now Institute exploit)
campaign · campaign:friendly-fire-ai-agent-defensive-hijack
AI Now Institute proof-of-concept in which a two-layer indirect prompt injection embedded in an untrusted repository's own files (a decoy Go source paired with a malicious binary, plus a README steering the agent to run a bundled script) hijacks Claude Code (auto-mode) and OpenAI Codex CLI (auto-review) into executing attacker code during a defensive security review, achieving RCE with no hooks, plugins, MCP servers or config files required (AI Now Institute, 2026-07-08).
Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
AI Now Institute PoC turns an untrusted library's own files into RCE when Claude Code or Codex CLI review it…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about Friendly Fire (AI Now Institute exploit), newest first. Check the date before acting on an older one.
- Do not point an agentic coding assistant with command-execution ability (Claude Code auto-mode, Codex auto-review, or equivalents) at untrusted third-party or open-source code, including automated dependency-update review in CI/CD, treat the reviewed repository as attacker-controlled input, not trusted data.2026-07-11AI Now Institute PoC turns an untrusted library's…
- Where such agents are used, run them in isolated, credential-minimised environments and do not treat sandboxing as sufficient: the researchers show an in-sandbox RCE can be chained to escape (citing CVE-2026-39861 and CVE-2026-25725 against Claude Code's own sandbox).2026-07-11AI Now Institute PoC turns an untrusted library's…
- Hunt on developer/CI hosts for coding-agent processes spawning a Unix shell or executing a repository-supplied binary/script (e.g. a2026-07-11AI Now Institute PoC turns an untrusted library's…
security.shor similar) during a review task, and for outbound network or credential access from such child processes.
Defender insights
What each entry about Friendly Fire (AI Now Institute exploit) tells a defender to do, newest first.
Triage
Story timeline
ATT&CK techniques (3 across 2 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessSupply Chain Compromise: Compromise Software Dependencies and Development Tools
- ExecutionCommand and Scripting Interpreter: Unix Shell · User Execution: Malicious File
Initial Access TA0001
T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development Tools×1
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.
Evidence: 2026-07-11/friendly-fire-prompt-injection-rce-defensive-ai-agents · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-07-11/friendly-fire-prompt-injection-rce-defensive-ai-agents · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-07-11/friendly-fire-prompt-injection-rce-defensive-ai-agents · ATT&CK page ↗
Entries about Friendly Fire (AI Now Institute exploit) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- ainowinstitute.org1 (50%)
- infosecurity-magazine.com1 (50%)