'InstallFix' Attacks Spread Fake Claude Code Sites
ID: 80d8d586-3866-5da1-82ca-11a6b286ef39
STIX ID: report--80d8d586-3866-5da1-82ca-11a6b286ef39
Feed Name: Dark Reading
Threat Score
Push Security disclosed an "InstallFix" campaign that uses Google-sponsored ads and near-identical cloned Claude Code install pages to trick users into pasting malicious terminal commands that install Amatera Stealer, an infostealer capable of exfiltrating developer credentials and compromising enterprise development environments; attackers also leverage legitimate hosting providers for deceptive domains and IoCs are short-lived.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
