Fake Claude Code Installers Used to Steal Developer Browser Credentials
Cybersecurity researchers uncovered an active malware campaign targeting software developers through fake installation pages impersonating Anthropic’s Claude Code platform. The operation relies heavily on social engineering and malicious search advertisements to trick victims into downloading or executing malware disguised as legitimate AI development tooling. The campaign demonstrates a growing trend where attackers exploit the popularity and rapid adoption of AI-assisted coding tools to compromise developer environments and steal sensitive browser data. The attack typically begins when a developer searches online for terms such as “install Claude Code” or “Claude Code CLI.” Attackers purchase sponsored search advertisements that appear above legitimate results, redirecting victims to convincing lookalike websites that closely mimic official Claude documentation pages. These fake pages replicate branding, layouts, installation guides, and command-line instructions in order to appear ...