Claude Code leak used to push infostealer malware on GitHub

2026-04-03T01:23:33Z39f5da8efb0f1d59af1f315bcc3f10e4119cd0ac2387eefdf105b447e593635c
$280m lossadmin accessauthentication bypasscisco imcclaude code leakcrystalratdefi governance attackdrift protocolf5 big-ip apmfake repositoriesgithub supply-chain abusehybrid cybercrimeinfostealerip reputation evasionmail interceptionmalicious updatespre-auth rceprogress sharefilerat stealer keyloggerrce exposureresidential proxiestrueconf zero-dayunauthenticated exfiltrationvacant homesvidar

What happened

Multiple high-impact incidents and trends were reported: threat actors are weaponizing the leaked Claude Code via fake GitHub repos to deliver Vidar infostealer malware; a sophisticated governance attack drained at least $280M from the Drift Protocol; researchers found residential proxies bypass IP-reputation checks at scale; attackers are abusing vacant homes and postal fraud for hybrid mail-enabled fraud; two new Progress ShareFile flaws can be chained for pre-auth RCE and unauthenticated data exfiltration; 14,000+ F5 BIG‑IP APM instances remain exposed to active RCE exploitation and Cisco’s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
39f5da8efb0f1d59af1f315bcc3f10e4119cd0ac2387eefdf105b447e593635c
Enrichment time
2026-04-03T01:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.