logo

InstallFix: Not the application you were looking for

ID: 3fbc2b73-1675-5fd0-8fab-23d0fe8278fc

STIX ID: report--3fbc2b73-1675-5fd0-8fab-23d0fe8278fc

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-27

...
...

InstallFix is a widespread watering‑hole campaign that clones official installation documentation for Claude Code and lures users into executing attacker-supplied commands; variants include use of mshta with MSIX polyglot files and other living-off-the-land techniques to evade analysis. The report documents observed scale (dozens of cloned pages and scans), outlines indicators, and recommends mitigations for Windows and macOS such as DNS filtering, clipboard protections, WDAC, EDR/MDM, and Group Policy restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.