logo

They thought they were downloading Claude Code source. They got a nasty dose of malware instead

ID: 249778a4-293e-5044-b81d-7eb0fadbd81c

STIX ID: report--249778a4-293e-5044-b81d-7eb0fadbd81c

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Zscaler researchers discovered a malicious GitHub repository masquerading as leaked Claude Code source that distributed a Rust dropper which installs Vidar infostealer and GhostSocks proxy; the repo appeared high in search results, had many forks/stars, and included a malicious .7z release. The report notes active exploitation, provides IOCs (repo links and hashes), and warns defenders to avoid downloading trojanized repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.