Story · Straiker Blog
Fable to Haiku: How a Malicious Repo Tricked Claude Code Into Running Malware (Straiker Blog)
blog post · Story page

Straiker's account of a repository written to be read by a coding agent: it got Claude Code to downgrade its own review from Fable to Haiku, steered the agent around the payload, and a routine test run executed the malware. One vendor's demonstration, on the trust boundary every coding agent stands on.
In plain words
- Straiker demonstrated how a project's files tricked Claude Code, an artificial intelligence coding assistant, into running harmful software.
- Instructions in the files made the assistant switch to a weaker system for checking the code.
- The assistant ran the harmful code during routine tests after being steered away from inspecting it.
- For developers, the case exposes a risk when a project can influence how its own code gets checked.
Appeared in
- Dormant prompt injections land on nine production agents where direct orders fail
Sep 23, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
