High-Risk Backdoor Found in AI Coding Assistant, Posing Data Privacy Threat
A recent monitoring report from China's Ministry of Industry and Information Technology (MIIT) has revealed a critical security vulnerability in Claude Code, a popular AI-powered programming tool. Developed by Anthropic, the tool automates code generation and debugging but contains a hidden surveillance mechanism in certain versions.
Nature of the Vulnerability and Risks
The core issue affects Claude Code versions 2.1.91 through 2.1.196. These versions can transmit sensitive user data—such as geographic location and device identifiers—to remote servers without obtaining user consent.
This backdoor means developers' coding activities and environments could be monitored unknowingly. For organizations, if the tool is used in projects involving proprietary or internal systems, it raises the risk of exposing commercial secrets or critical data.
Recommended Actions and Mitigation
MIIT has issued formal guidance urging developers and enterprises to take immediate steps:
- Immediate Verification and Action: Check the version of Claude Code on all development workstations. If it falls within the affected range (2.1.91–2.1.196), uninstall it promptly or upgrade to the latest patched version provided by the vendor.
- Strengthen Network Security Controls: Within corporate networks, especially in segments handling core business operations, restrict outbound connections from development tools. Enhance monitoring of network traffic to detect and block any unauthorized data exfiltration attempts.
This incident serves as a stark reminder for developers and companies relying on third-party AI tools. While leveraging technological convenience, integrating robust security assessments and access controls remains paramount.