Claude Code Sessions Spawn Reverse Tunnels and LaunchAgent Persistence on macOS

Claude Code activity on a macOS developer machine has raised a difficult security question: when does convenient automation become a serious exposure? A new Elastic investigation found a session that opened reverse tunnels, sent login details to temporary public addresses, and created LaunchAgent entries that could survive logout or restart. The activity did not look […]

This article has been indexed from Cyber Security News

Read the original article: