logo

Attackers Abuse SEO Poisoning to Spread Fake Gemini and Claude Installers

ID: 9c0c52ee-3e3e-5ffd-b017-e97f5da1fc16

STIX ID: report--9c0c52ee-3e3e-5ffd-b017-e97f5da1fc16

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Lucas Martin

...
...

Threat actors are using SEO-poisoned, typosquatted installation pages for popular AI developer tools (Gemini CLI, Claude Code, Node.js, etc.) to lure developers into pasting a one-line PowerShell command that installs a legitimate package while loading a fileless infostealer. The malware disables ETW/AMSI, runs in memory, harvests session cookies, credentials, VPN and remote access data, and exfiltrates to C2 servers; researchers observed multiple related domains, a hosting IP, C2 endpoints, and a downloader script name and recommend hunting for 'irm | iex' patterns and enforcing PowerShell constrained language on developer workstations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.