Anthropic introduced Claude Code mods, JavaScript or TypeScript functions that can intercept session events and change prompts, tool calls, permission handling, and the application interface. The feature is enabled by default in Claude Code version 2.1.287 and later, with mods distributed through the existing plugin mechanism. Mods expand a customization ecosystem that already includes project memory, workflow hooks, settings, and Model Context Protocol (MCP) tool connections.
Mod code executes locally with access to the developer’s machine through Claude Code, making publisher trust and source-code review important security controls. Anthropic recommends inspecting mod source code and installing only mods from trusted publishers. For Team and Enterprise users, and machines with managed settings, Anthropic’s sec-default guard loads before user-installed mods and prevents them from overriding permission-deny rules by default. Outside those guarded environments, mods can override some permission decisions. Security teams should verify which guardrails apply before approving mods; the reported concern is an extension trust boundary, not a disclosed compromise or confirmed vulnerability.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Anthropic introduced JavaScript and TypeScript mods that can modify prompts, tool calls, permission handling, and the interface, enabled by default in Claude Code 2.1.287 and later. Mods execute locally; Team, Enterprise, and managed environments load a security guard that prevents user-installed mods from overriding permission-deny rules by default.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcecode.claude.com
Open sourcecode.claude.com
Open sourcecode.claude.com
Open sourcecode.claude.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.