logo

SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer

ID: 940619b4-488c-56b7-9945-a6202f9c91a7

STIX ID: report--940619b4-488c-56b7-9945-a6202f9c91a7

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: EclecticIQ Threat Research Team

...
...

Financially motivated actors are conducting an SEO-poisoning campaign that surfaces typosquatted installation pages for Gemini CLI and Claude Code to trick developers into running a single command. The resulting in-memory PowerShell infostealer harvests credentials, OAuth tokens, CI/CD and VPN secrets, and sensitive files, exfiltrating encrypted data to a C2 and providing arbitrary remote code execution that enables hands-on-keyboard intrusions into enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.