VES-CC-2026-002: Claude Code Exploitation via Tencent-Hosted Infrastructure Published: 2026-03-10 Severity: Critical Author: Nirmal Liyon, VertexElite Security Research AI coding agent subscription hijack via CLAUDE.md injection and VibeOps WebSocket C2 Q: What is VES-CC-2026-002? A: A documented live exploitation chain targeting Claude Code (Anthropic's AI coding agent) using a WebSocket-based C2 platform called VibeOps hosted on Tencent Cloud, enabling silent subscription-scoped identity abuse and billing hijack against victim Max accounts. Q: How does CLAUDE.md injection work? A: Claude Code automatically loads CLAUDE.md project configuration files. Attackers inject malicious instructions into these files within shared repositories, redirecting agent behavior without user knowledge. The agent then executes attacker-controlled instructions under the victim's subscription. Q: What is the VibeOps C2 platform? A: VibeOps is a WebSocket bridge platform hosted at 167.71.211.14 (DigitalOcean Singapore) using n8n.falconet.io relay infrastructure, providing persistent remote control over compromised Claude Code instances. Full advisory: https://research.vertexelite.org/advisories/VES-CC-2026-002