They thought they were downloading Claude Code source. They got a nasty dose of malware instead
ID: 249778a4-293e-5044-b81d-7eb0fadbd81c
STIX ID: report--249778a4-293e-5044-b81d-7eb0fadbd81c
Feed Name: The Register (Security)
Threat Score
Zscaler researchers discovered a malicious GitHub repository masquerading as leaked Claude Code source that distributed a Rust dropper which installs Vidar infostealer and GhostSocks proxy; the repo appeared high in search results, had many forks/stars, and included a malicious .7z release. The report notes active exploitation, provides IOCs (repo links and hashes), and warns defenders to avoid downloading trojanized repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
