Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-10

HighPrimary

GhostJacking: Poisoned Observability Logs Turn Claude Code Against Its Operator to Hijack DNS and Steal Credentials

Analysis of the GhostJacking exploit presented at DEF CON 2026, where poisoned Sentry, Datadog, or Cloudflare logs executed commands in Claude Code.

Claude CodeTool execution / MCPIndirect Command Injection via Observability LogsDeveloper workstation / Observability stack integrations

What happened

An attacker injects malicious instructions into web server logs; the developer tasks Claude Code with reviewing Sentry/Datadog logs, and the agent executes the payload.

Why it matters

Complete workstation compromise, DNS hijacking, and exfiltration of AWS/GitHub keys and session tokens.

Missing authorization check

All system command execution and host filesystem modifications must require cryptographically-signed authorization receipts.

Would PP block it?

Even if a poisoned log overrides Claude Code's system prompt and instructs it to modify system files or run shell scripts, the agent cannot execute these actions. PP's Runtime Gate intercepts all tool executions and requires a valid, cryptographically-signed receipt. Since the log payload cannot forge the human operator's private key signature, the RCE payload fail-closes.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-10

    Tenet Security presents GhostJacking at DEF CON 2026, demonstrating 90% exploit success against Claude Code.

  2. 2026-08-10

    Tenet Security publishes a blog post detailing observability log injection vectors.

Technical breakdown

  • The attacker triggers a web application error carrying a malicious prompt injection payload inside a HTTP header.
  • The payload is logged by Cloudflare, Sentry, or Datadog.
  • The operator runs Claude Code locally to debug the incident. The agent fetches and parses the logs containing the payload.
  • The model merges the log text into its active execution thread, executing the embedded shell commands (RCE).

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Runtime Gate, local tool executor runtime
Still needs
PP does not block the agent from reading or rendering the poisoned log files within its execution boundary.
Receipt required for
Running shell commands, writing system files, or accessing external network resources

PP's Runtime Gate intercepts all shell executions and prevents unauthorized commands regardless of log poisoning.

Start small

Put the relevant gate at this action boundary.

This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop