logo

Fake Claude Code Page Pushes PowerShell Stealer at Devs

ID: aed3570f-9c78-5d6b-a365-e07afcdf33cb

STIX ID: report--aed3570f-9c78-5d6b-a365-e07afcdf33cb

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

...
...

Ontinue's Cyber Defense Center reported a campaign that used lookalike Claude Code installation pages and sponsored search ads to trick developers into running a PowerShell installer which fetched a large obfuscated loader; the loader enumerated Chromium-family browsers and reflectively injected a native helper to exploit a browser COM interface (IElevator2/legacy fallback) to recover App-Bound Encryption keys and exfiltrate cookies, credentials and payment data, persisting via a scheduled task while excluding certain regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.