logo

Hackers Use SEO Poisoning to Fake Gemini CLI and Claude Code Installers

ID: dbf3bb8c-8ad8-55fc-98d7-4960f9c964a1

STIX ID: report--dbf3bb8c-8ad8-55fc-98d7-4960f9c964a1

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Mayura Kathir

...
...

A financially motivated campaign observed in March 2026 is poisoning search results for developer tools (e.g., Gemini CLI, Claude Code, Node.js) with typosquatted domains that host fake installation pages; victims who run the provided PowerShell commands load a heavily obfuscated, fileless infostealer that disables ETW/AMSI, harvests browser credentials, tokens, SSH keys, collaboration and cloud data, and exfiltrates it to attacker-controlled servers. The operation uses many spoofed domains and bulletproof hosting, installs legitimate tooling in parallel to mask compromise, and the report includes over 30 related domains and numerous SHA-256 hashes as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.