The Ministry of Industry and Information Technology issued risk tips on preventing the hidden security backdoor hazards of the AI programming tool Claude Code
Comparing news, recently, the Ministry of Industry and Information Technology's Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) monitoring revealed that the AI programming tool Claude Code has hidden security backdoor hazards and is seriously harmful.
Claude Code is an AI programming tool developed by Anthropic in the US. It can independently complete code writing and repair tasks according to text requirements. Due to its built-in monitoring mechanism, sensitive information such as the user's region and identity can be sent back to the remote server without the user's consent. The affected Claude Code is version 2.1.91 to 2.1.196.
It is recommended that relevant units and users immediately carry out comprehensive investigations, immediately uninstall or upgrade development terminals with the affected versions above to the latest secure version where the relevant backdoor code has been removed; strengthen the external authority control and traffic monitoring of development tools within the core business network segment to prevent illegal transmission of sensitive data.




