Hackers spread malware to developers via fake Claude code

The latest AI source code leakage phenomenon that poses a serious threat

Technology developers and practitioners are now facing a new threat due to leakage of the source code of the latest artificial intelligence (AI) tool belonging to the anthropic company, Claude Code. This leak is not only an internal problem of the company, but also has the potential to pose a big risk to the user and the security system as a whole.

The leak occurred on March 31, when Anthropic accidentally shared the entire client-side source code from Claude Code via a JavaScript source map of 59.8 MB in a published NPM package. This data includes 513,000 lines of TypeScript code that is not obscured in 1,906 files. The information revealed includes orchestration logic, licensing systems, hidden features, to the internal security details of Claude Code—a terminal-based AI agent designed to execute autonomous coding tasks.

The exposed code was quickly downloaded by thousands of users and re-shared on GitHub through thousands of forks. This gap is then exploited by cyber criminals to trap curious users. According to the ZScaler report, the hackers made a fake GitHub repository to distribute Vidar’s infostealer.

One of the accounts identified, “IDBZOOMH”, uploaded a fake leak with the lure of “Unlocked Enterprise Features) and without usage restrictions. To capture victims, this repository has been optimized in SEO so that it appears at the top of the Google search engine with keywords such as “Leaked Claude Code”.

Trapped users will download a 7-zip archive containing a rust-based executable file called claudecode_x64.exe. Once executed, the dropper will install Vidar Infostealer or commodity malware that functions to steal sensitive information from the victim’s device and Ghostsocks or network traffic proxies to disguise the illegal activities of hackers.

Vidar is a very dangerous malware. Vidar retrieves all usernames and passwords stored in Google Chrome, Edge, or Firefox. Vidar also stole credit card data stored for auto-fill. In addition, Vidar can steal active cookies. This means that the hacker can login to your Gmail, Slack, or banking account without the need to enter a password or bypassing two-step verification (2FA), because the system assumes the hacker is you who are logged in.

ZScaler researchers found that the malicious archive is updated regularly, which means there is a possibility that other malicious payloads will be added in the future. In addition, it was found a second repository with identical code that was strongly suspected to be operated by the same actor as the distribution strategy experiment.

Security experts warn developers not to download a copy of Claude Code source code from unofficial sources on GitHub. In addition to the legal risks related to copyright, cyber security threats that lurk can have fatal consequences for the integrity of personal data and company infrastructure.

Anthropic itself is still trying to mitigate the impact of the leakage of their intellectual assets. However, this incident is a strong warning to all technology stakeholders about the importance of digital resource security and the need for stricter supervision of the distribution of source code.

Leave a Reply

Your email address will not be published. Required fields are marked *


Baca Juga

Back to top button

Adblock Detected

LidahTekno.com is supported by Google Adsense advertising to provide content for you.Please consider disabling AdBlocker or adding us to your whitelist so we can continue providing the best technology information and tips.Thank you for your support!