<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Claude on s0ld13r's blog</title><link>https://www.s0ld13r.kz/tags/claude/</link><description>Recent content in Claude on s0ld13r's blog</description><generator>Hugo -- 0.147.0</generator><language>en-us</language><lastBuildDate>Thu, 16 Apr 2026 14:52:15 +0500</lastBuildDate><atom:link href="https://www.s0ld13r.kz/tags/claude/index.xml" rel="self" type="application/rss+xml"/><item><title>Claude Code Hooks as Initial Access &amp; Persistence</title><link>https://www.s0ld13r.kz/posts/claude-code-backdoor/</link><pubDate>Thu, 16 Apr 2026 14:52:15 +0500</pubDate><guid>https://www.s0ld13r.kz/posts/claude-code-backdoor/</guid><description>&lt;blockquote>
&lt;p>&lt;strong>DISCLAIMER:&lt;/strong>
This article is intended strictly for educational and research purposes. The techniques, tools, and concepts discussed here are designed to enhance understanding of adversary tactics, improve defensive capabilities, and support authorized Red Team assessments. Any unauthorized or malicious use of the information provided is strongly condemned and may be illegal.&lt;/p>&lt;/blockquote>
&lt;h2 id="intro">Intro&lt;/h2>
&lt;p>&lt;img alt="Malicious VSCode Task" loading="lazy" src="https://www.s0ld13r.kz/vscode_task_lazarus.jpg">&lt;/p>
&lt;p>Do you remember the &lt;a href="https://github.com/SaadAhla/VSCode-Backdoor">VSCode task backdoor&lt;/a> ? The core idea was simple: you can&amp;rsquo;t blindly trust projects you open in your editor. An attacker could embed a surprise in &lt;code>.vscode/tasks.json&lt;/code>, and the moment you trusted the workspace, a loader would silently fire in the background and your machine will be compromised. This technique was weaponized by DPRK affilated &lt;a href="https://radar.securityalliance.org/vs-code-tasks-abuse-by-contagious-interview-dprk/">Lazarus group&lt;/a> in their campaigns against IT companies.&lt;/p></description></item></channel></rss>