Hackers Use Fake Claude Code Installation Page to Spread InstallFix Infostealer
Claude Code is an Anthropic development tool that helps users write and modify code from a terminal. Because development environments often contain source code, API keys, cloud credentials and cryptocurrency wallet data, a successful attack using a fake installation page could also compromise corporate systems and supply-chain security.
The InstallFix attack disclosed on March 9 mimicked a Claude Code installation page and tricked users into copying and running a curl-to-bash command, circumventing the caution typically associated with downloads. The malware then installed Amatera Stealer to collect browser passwords, session tokens and development-environment credentials. No financial losses were publicly reported.
All Coverage
3 original reportsThe Backstory
The history behind this eventAttackers Impersonate Anthropic's Claude Website to Spread PlugX Remote-Access Trojan
Anthropic's Claude is a generative AI service widely used by businesses and individuals, prompting attackers to create fake Claude Pro websites and download pages that trick users into installing malware. PlugX is a remote-access trojan that often evades detection through DLL side-loading, posing a threat to accounts, business data and corporate network security.
A cybersecurity company recently found that Claude Pro installers offered by the fake websites use DLL side-loading to deploy PlugX. Once a device is infected, hackers can remotely capture screenshots, log keystrokes and monitor the device. Researchers have published the associated indicators of compromise to help users and companies detect infections. Current reports do not disclose when the campaign was discovered, the number of victims or the amount of financial losses.
Hackers Impersonate Anthropic's Claude Code to Spread Vidar Stealer as APT28 Targets Routers
Anthropic's Claude Code is an AI coding tool for developers, but hackers are exploiting its name to distribute the Vidar information stealer in an effort to obtain credentials and sensitive data. The incidents also involve network-device attacks by the Russian hacking group APT28 and a European Commission data breach linked to a compromise of the Trivy supply chain, highlighting the intertwined risks of brand impersonation, router vulnerabilities and open-source tools.
An April 8 cybersecurity report disclosed that APT28 had hijacked SOHO routers on a large scale, using DNS hijacking to redirect victims to attacker-controlled adversary-in-the-middle, or AiTM, infrastructure. Separately, a user was infected with Vidar after downloading a file posing as Claude Code. The European Commission also confirmed that its data breach was linked to the Trivy supply-chain attack. Current disclosures have not specified the number of affected devices, the scale of the leak or the financial losses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.