Apparently there's a bug in iTerm2 for macOS that allows for malicious command execution in combination with tmux:

If you're using iTerm2, get version 3.3.6 or newer:

