Fake Claude Code Spreads Malware to Windows, macOS Users
ID: c843e769-3f86-5b81-bf59-a066744b5874
STIX ID: report--c843e769-3f86-5b81-bf59-a066744b5874
Feed Name: TechRepublic Security
Attackers are cloning popular developer installation pages and using malvertising to drive victims to fake install instructions that execute altered one-line install commands; the campaign delivers the Amatera information-stealing malware via staged execution (cmd.exe -> mshta.exe) and hides infrastructure on trusted hosts/CDNs. The report details delivery methods, evasion techniques, and recommends mitigations such as verifying URLs/commands, DNS filtering, EDR monitoring, allow-listing trusted repositories, and enforcing least-privilege on developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
