Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users
2026-05-30T20:51:44Z•83e6ec0e60caf32015d1cdbc3d593557c9bad34c5b27ba09b45d9067064cf4bf
Claude (Anthropic)ClickFixGeminiNimbus ManticoreSEO poisoningbrowser credentialscredential theftdetection evasiondeveloper-targetedfileless malwareinfostealermacOSphishingsupply chaintrojanized installers
What happened
Multiple active campaigns reported: fake Anthropic/Gemini/Claude websites and SEO-poisoned installer pages are distributing a fileless infostealer that steals browser credentials and evades detection, specifically targeting Claude Code users and developers. Related incidents include trojanized Zoom installers attributed to Iran-linked Nimbus Manticore used against US firms, and a ClickFix macOS infostealer compromise of a retail site. Overall activity leverages SEO poisoning, trojanized installers, and fileless techniques to harvest credentials and developer secrets, increasing risk to AI-tool
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 83e6ec0e60caf32015d1cdbc3d593557c9bad34c5b27ba09b45d9067064cf4bf
- Enrichment time
- 2026-05-30T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.