Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads
ID: 1bcdef3d-b226-58ee-99c9-9960259a950a
STIX ID: report--1bcdef3d-b226-58ee-99c9-9960259a950a
Feed Name: TrendAI Security Blog
In late March 2026 an accidental npm publish exposed Anthropic's Claude Code source, and within 24 hours threat actors used the ensuing hype to host trojanized “leaked” downloads on disposable GitHub repositories; the delivered Rust dropper (TradeAI.exe) deploys Vidar stealer and GhostSocks proxy, uses robust sandbox/VM evasion, XOR/string obfuscation, dead-drop C2 resolvers (Steam/Telegram), and Windows Defender/evasion techniques—the report documents campaign scale, technical analysis, IOCs, MITRE-mapped TTPs, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
