logo

Anthropic Claude Code Leak

ID: 27334acb-377a-5336-813a-308302a2b4ef

STIX ID: report--27334acb-377a-5336-813a-308302a2b4ef

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-05-01

...
...

ThreatLabz discovered malicious GitHub repositories posing as a “Claude Code” leak that distribute a Rust-based dropper (ClaudeCode_x64.exe) which drops Vidar v18.7 (an information stealer) and GhostSocks (a proxy). The repositories are easily discoverable via search results, are actively updated, and appear hosted under multiple accounts by the same actor (idbzoomh); releases contain malicious ZIP archives and the README lures users to download the fake leaked source.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.