Fake Claude Code installation-page infostealer campaign targeting developers
Campaign
Summary
Hide ▲
Show ▼
A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, putting browser credentials and payment data at risk. The lure pages imitate legitimate documentation while swapping the install command to an attacker domain, turning a normal install flow into malware delivery. The operation was tied to three domains registered in April 2026 and shows sustained, multi-step targeting rather than a one-off lure.
Related Happenings
Claude Chrome forged-click and skipPermissions security flaw
Vulnerability
H score35
First: 14.07.2026 20:27
Last: 14.07.2026 20:27
Sources 1
About this happening:
Claude for Chrome still accepts synthetic clicks on its onboarding button, letting a rogue extension trigger allowlisted tasks for Gmail, Google Docs, and Calendar...
Claude Chrome forged-click and skipPermissions security flaw
VulnerabilityAbout this happening: Claude for Chrome still accepts synthetic clicks on its onboarding button, letting a rogue extension trigger allowlisted tasks for Gmail, Google Docs, and Calendar...
Brave Software launches paid Brave Origin browser
Commercial Activity
H score0
First: 05.06.2026 00:37
Last: 05.06.2026 00:37
Sources 1
About this happening:
Brave Software launched Brave Origin, a paid browser variant that removes cryptocurrency, AI, rewards, and other monetization features while keeping Brave Shields....
Brave Software launches paid Brave Origin browser
Commercial ActivityAbout this happening: Brave Software launched Brave Origin, a paid browser variant that removes cryptocurrency, AI, rewards, and other monetization features while keeping Brave Shields....
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
Campaign
H score33
First: 22.05.2026 14:30
Last: 22.05.2026 14:30
Sources 1
About this happening:
Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
CampaignAbout this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
MuddyWater broad cyber-espionage campaign across sectors and countries
Campaign
H score37
First: 14.05.2026 00:59
Last: 14.05.2026 00:59
Sources 1
About this happening:
MuddyWater was tied to a 2026 espionage campaign affecting at least nine organizations across nine countries on four continents, with victims in industrial a...
MuddyWater broad cyber-espionage campaign across sectors and countries
CampaignAbout this happening: MuddyWater was tied to a 2026 espionage campaign affecting at least nine organizations across nine countries on four continents, with victims in industrial a...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
Campaign
H score56
First: 12.05.2026 14:29
Last: 12.05.2026 14:29
Sources 1
About this happening:
GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
CampaignAbout this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Timeline
-
11.05.2026 17:00 2 articles · 2mo ago
Fake Claude Code install pages deliver Chromium infostealer to developers
Initial DisclosureOntinue detailed a fake Claude Code installation-page campaign that used sponsored search results for "install claude code" to send developers to a lookalike page, swapped the legitimate Anthropic install host for an attacker-controlled domain, and launched a 600 KB obfuscated PowerShell loader that injected a 4608-byte native helper into Chromium-family browsers, recovered the App-Bound Encryption key, and exfiltrated cookies, passwords and payment data from developer workstations while a scheduled task maintained persistence and excluded hosts in Iran, Russia and other CIS members.
Show sources
- Fake Claude Code Page Pushes PowerShell Stealer at Devs — www.infosecurity-magazine.com — 11.05.2026 17:00
- Fake Claude Code Page Pushes PowerShell Stealer at Devs — www.infosecurity-magazine.com — 11.05.2026 17:00