Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fake Claude Code installation-page infostealer campaign targeting developers

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, putting browser credentials and payment data at risk. The lure pages imitate legitimate documentation while swapping the install command to an attacker domain, turning a normal install flow into malware delivery. The operation was tied to three domains registered in April 2026 and shows sustained, multi-step targeting rather than a one-off lure.

Related Happenings

Claude Chrome forged-click and skipPermissions security flaw

Vulnerability
H score35 First: 14.07.2026 20:27 Last: 14.07.2026 20:27 Sources 1

About this happening: Claude for Chrome still accepts synthetic clicks on its onboarding button, letting a rogue extension trigger allowlisted tasks for Gmail, Google Docs, and Calendar...

Brave Software launches paid Brave Origin browser

Commercial Activity
H score0 First: 05.06.2026 00:37 Last: 05.06.2026 00:37 Sources 1

About this happening: Brave Software launched Brave Origin, a paid browser variant that removes cryptocurrency, AI, rewards, and other monetization features while keeping Brave Shields....

Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign

Campaign
H score33 First: 22.05.2026 14:30 Last: 22.05.2026 14:30 Sources 1

About this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...

MuddyWater broad cyber-espionage campaign across sectors and countries

Campaign
H score37 First: 14.05.2026 00:59 Last: 14.05.2026 00:59 Sources 1

About this happening: MuddyWater was tied to a 2026 espionage campaign affecting at least nine organizations across nine countries on four continents, with victims in industrial a...

Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials

Campaign
H score56 First: 12.05.2026 14:29 Last: 12.05.2026 14:29 Sources 1

About this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...

Timeline

  1. 11.05.2026 17:00 2 articles · 2mo ago

    Fake Claude Code install pages deliver Chromium infostealer to developers

    Initial Disclosure

    Ontinue detailed a fake Claude Code installation-page campaign that used sponsored search results for "install claude code" to send developers to a lookalike page, swapped the legitimate Anthropic install host for an attacker-controlled domain, and launched a 600 KB obfuscated PowerShell loader that injected a 4608-byte native helper into Chromium-family browsers, recovered the App-Bound Encryption key, and exfiltrated cookies, passwords and payment data from developer workstations while a scheduled task maintained persistence and excluded hosts in Iran, Russia and other CIS members.

    Show sources