A single GitHub issue could have hijacked Anthropic’s own Claude Code action and poisoned every project that uses it