logo

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads

ID: 1bcdef3d-b226-58ee-99c9-9960259a950a

STIX ID: report--1bcdef3d-b226-58ee-99c9-9960259a950a

Feed Name: TrendAI Security Blog

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-08-14

...
...

In late March 2026 an accidental npm publish exposed Anthropic's Claude Code source, and within 24 hours threat actors used the ensuing hype to host trojanized “leaked” downloads on disposable GitHub repositories; the delivered Rust dropper (TradeAI.exe) deploys Vidar stealer and GhostSocks proxy, uses robust sandbox/VM evasion, XOR/string obfuscation, dead-drop C2 resolvers (Steam/Telegram), and Windows Defender/evasion techniques—the report documents campaign scale, technical analysis, IOCs, MITRE-mapped TTPs, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.