A single fake error report hijacked Claude Code in controlled testing — the agent ran the attacker's code with the ...