logo

Faux ChatGPT, Claude API Packages Deliver JarkaStealer

ID: 1066e196-d090-5bf5-8f9d-7ee7dd26cbea

STIX ID: report--1066e196-d090-5bf5-8f9d-7ee7dd26cbea

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-11-22

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Two malicious PyPI packages, gptplus and claudeai-eng, posed as tools to access ChatGPT and Claude but instead dropped a Java JAR containing the JarkaStealer infostealer; the packages survived on PyPI for about a year, were downloaded over 1,700 times each across multiple countries, and are capable of stealing browser data, session tokens (Telegram, Discord, Steam), and screenshots — a supply-chain style campaign targeting developers and users seeking free GenAI access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.