logo

Claude Code leak used to push infostealer malware on GitHub

ID: bd62ac81-aaf1-5350-912b-acdcda95d390

STIX ID: report--bd62ac81-aaf1-5350-912b-acdcda95d390

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors exploited Anthropic's accidental Claude Code source-code leak by publishing SEO-optimized fake GitHub repositories purporting to host the leaked files; downloads contained a Rust dropper (ClaudeCode_x64.exe) that installs the Vidar info-stealer and GhostSocks proxy. Zscaler researchers observed frequent updates to the malicious archive and multiple repositories likely operated by the same actor, indicating an active campaign that targets curious users searching for the leak.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.