Mark RadarMARK RADAR
About
EN
Sign in

China’s MIIT Warns of Claude Code Backdoor, Orders Upgrades

3 reports · First detected 2026-07-08 · Last active 2026-07-09

Claude Code, an AI-assisted software-development tool created by Anthropic—an AI company in which Amazon has invested a cumulative $13 billion—has gained popularity among developers worldwide for its efficient code-generation capabilities. However, the tool’s built-in “anti-distillation mechanism” has been accused of transmitting users’ private information back during data transfers, raising cybersecurity concerns. The issue affects not only the protection of companies’ core source code but has also escalated into a matter of national information security and regulatory compliance.

China’s Ministry of Industry and Information Technology issued a security warning on July 8, 2026, saying Claude Code versions v2.1.91 through v2.1.196 contained a serious backdoor vulnerability that uploaded geolocation and identity information. The ministry ordered Chinese companies to uninstall the tool or upgrade immediately. Anthropic said it had removed the mechanism in updates released after July 1 and stressed that its services were already prohibited for users in mainland China.

All Coverage

3 original reports

The Backstory

The history behind this event
Microsoft Discloses Claude Code Prompt-Injection Flaw That Could Leak CI/CD Credentials2026-06-07 · 1 reports · similarity 0.80

Anthropic’s Claude Code is a development environment that uses generative AI to help developers read and write code and operate tools. Prompt injection can override a user’s intent if the system mistakes text in a GitHub repository for trusted instructions. Microsoft said the flaw posed a significant risk because CI/CD systems often hold highly privileged credentials such as deployment keys and cloud tokens.

Microsoft security researchers recently disclosed that attackers could hide malicious prompts in GitHub content, inducing Claude Code to execute unintended commands and send CI/CD credentials to an external destination. Anthropic has patched the flaw. Users of version 2.1.128 and earlier are advised to upgrade immediately to reduce the risk of compromise to software supply chains and deployment environments.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)