Claude Code leak used to push infostealer malware on GitHub
2026-04-03T01:23:33Z•39f5da8efb0f1d59af1f315bcc3f10e4119cd0ac2387eefdf105b447e593635c
$280m lossadmin accessauthentication bypasscisco imcclaude code leakcrystalratdefi governance attackdrift protocolf5 big-ip apmfake repositoriesgithub supply-chain abusehybrid cybercrimeinfostealerip reputation evasionmail interceptionmalicious updatespre-auth rceprogress sharefilerat stealer keyloggerrce exposureresidential proxiestrueconf zero-dayunauthenticated exfiltrationvacant homesvidar
What happened
Multiple high-impact incidents and trends were reported: threat actors are weaponizing the leaked Claude Code via fake GitHub repos to deliver Vidar infostealer malware; a sophisticated governance attack drained at least $280M from the Drift Protocol; researchers found residential proxies bypass IP-reputation checks at scale; attackers are abusing vacant homes and postal fraud for hybrid mail-enabled fraud; two new Progress ShareFile flaws can be chained for pre-auth RCE and unauthenticated data exfiltration; 14,000+ F5 BIG‑IP APM instances remain exposed to active RCE exploitation and Cisco’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 39f5da8efb0f1d59af1f315bcc3f10e4119cd0ac2387eefdf105b447e593635c
- Enrichment time
- 2026-04-03T01:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.