logo

Cookie thieves caught stealing dev secrets via fake Claude Code installers

ID: c435245f-e19b-5f77-ab2f-d2053192e1d4

STIX ID: report--c435245f-e19b-5f77-ab2f-d2053192e1d4

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

Security researchers report an active campaign that lures developers with fake Claude Code installer pages which deliver an obfuscated PowerShell loader and a native helper that abuses Chromium's IElevator2/App‑Bound Encryption mechanism to decrypt and exfiltrate cookies, saved passwords, and payment methods; the attacks use Cloudflare-fronted domains, render the malicious command in landing-page HTML to evade scanners, and fall back to legacy elevation services if needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.