logo

Threat Actors Using Fake Claude Code Download to Deploy Infostealer

ID: 89dfc781-7c2f-5bef-8363-8879f51a6545

STIX ID: report--89dfc781-7c2f-5bef-8363-8879f51a6545

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** Cybercriminals are distributing an MSHTA-based infostealer by hosting convincing fake Claude Code download pages that invoke mshta.exe to fetch and run remote HTA scripts in memory; the malware harvests browser-stored credentials, session tokens, and other sensitive data, putting developers' code repositories and cloud credentials at risk, and defenders are advised to log and restrict mshta.exe activity and verify downloads from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.