3 Sources
[1]
Hackers Are Using Claude Code Leak As Bait to Spread Malware
A hacker was quick to pounce on the accidental leak of Anthropic's AI tool, Claude Code, by spreading malware on a GitHub page that claimed to host the source code. Cybersecurity vendor Zscaler spotted a hacker exploiting interest in the Claude Code leak to push two malware strains, Vidar and
[2]
Fake Claude Code source downloads actually delivered malware
Tens of thousands of people eagerly downloaded the leaked Claude Code source code this week, and some of those downloads came with a side of credential-stealing malware. A malicious GitHub repository published by idbzoomh uses the Claude Code exposure as a lure to trick people into downloading
[3]
Claude Code leak used to push infostealer malware on GitHub
Threat actors are exploiting the recent Claude Code source code leak by using fake GitHub repositories to deliver Vidar information-stealing malware. Claude Code is a terminal-based AI agent from Anthropic, designed to execute coding tasks directly in the terminal and act as an autonomous agent,
Share
Copy Link
Cybercriminals are weaponizing the recent Claude Code source code leak to distribute malware through deceptive repositories on GitHub. Security researchers at Zscaler discovered fake repositories delivering Vidar information stealer and GhostSocks proxy malware to unsuspecting users seeking the leaked Anthropic AI tool code. The malicious campaign highlights how quickly threat actors capitalize on high-profile AI-related leaks.
Cybercriminals moved swiftly to exploit the accidental Claude Code leak from Anthropic, creating fake GitHub repositories that deliver malware instead of the promised source code. On March 31, Anthropic inadvertently exposed the full client-side source code of its terminal-based AI agent through a 59.8 MB JavaScript source map accidentally included in the published npm package
3
. The leak contained 513,000 lines of unobfuscated TypeScript across 1,906 files, revealing orchestration logic, permissions, execution systems, and hidden features3
.
Source: PC Magazine
Cybersecurity firm Zscaler identified a malicious GitHub page from the account "idbzoomh" that claims to offer the leaked source code while actually distributing credential-stealing malware
1
. The deceptive repositories advertise "unlocked enterprise features" and no usage restrictions to lure victims3
. When users download the malicious .7z archive named "Claude Code - Leaked Source Code," they receive a Rust-based dropper executable called ClaudeCode_x64.exe2
. This dropper deploys Vidar v18.7, an information stealer that collects account credentials, credit card data, and browser history, alongside GhostSocks, a network traffic proxy tool that turns infected devices into proxy infrastructure for cybercriminals2
.
Source: BleepingComputer
The fake GitHub repositories were optimized for search engine results, appearing near the top of Google searches for queries like "leaked Claude Code"
3
. At least two trojanized Claude Code repositories remained active on GitHub at the time of reporting, with one accumulating 793 forks and 564 stars2
. Tens of thousands of people eagerly downloaded what they believed was the leaked source code this week2
. The malicious page even includes disclaimers about security alerts, claiming the application is "an experimental tool for Security Research" to avoid arousing suspicion when antivirus software triggers warnings1
.
Source: The Register
Related Stories
This malicious campaign follows a similar pattern observed in March when security firm Huntress warned about threat actors using OpenClaw, an AI agent platform, as a GitHub lure to deliver the same two payloads
2
. Zscaler researchers emphasized that this rapid movement to capitalize on buzzy new products and news events increases the chance of opportunistic compromise, especially through trojanized software and deceptive repositories2
. The researchers warn that threat actors are already seeding trojanized versions with backdoors, data exfiltration tools, and cryptominers, putting unsuspecting users who clone official-looking forks at immediate risk of compromise1
. The malicious archive is updated frequently, suggesting additional payloads may be added in future iterations3
. For developers and AI enthusiasts, this incident underscores the critical need for verification before downloading code from repositories, particularly during high-profile AI-related leaks when cybercriminals act quickly to exploit public interest.Summarized by
Navi
[1]
[2]
[3]
07 Mar 2026•Technology

27 May 2026•Technology

18 Mar 2026•Technology
1
Policy and Regulation

2
Technology

3
Policy and Regulation
