logo

Fake Claude Code install pages hit Windows and Mac users with infostealers

ID: d6492d9a-395e-5263-b209-ccde8012a199

STIX ID: report--d6492d9a-395e-5263-b209-ccde8012a199

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-03-09

Date Updated: 2026-04-28

...
...

Researchers observed a campaign dubbed “InstallFix” where attackers clone official install/docs pages and replace single‑line install commands with malicious scripts that install the Amatera infostealer. The technique targets non‑specialist users by leveraging sponsored search results and authentic-looking pages to harvest browser passwords, cookies, session tokens and other data on both macOS and Windows, enabling session hijacking and access to developer/cloud accounts; guidance includes verifying sources, avoiding copy‑paste commands, and using up‑to‑date anti‑malware protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.