Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users

2026-05-30T20:51:44Z83e6ec0e60caf32015d1cdbc3d593557c9bad34c5b27ba09b45d9067064cf4bf
Claude (Anthropic)ClickFixGeminiNimbus ManticoreSEO poisoningbrowser credentialscredential theftdetection evasiondeveloper-targetedfileless malwareinfostealermacOSphishingsupply chaintrojanized installers

What happened

Multiple active campaigns reported: fake Anthropic/Gemini/Claude websites and SEO-poisoned installer pages are distributing a fileless infostealer that steals browser credentials and evades detection, specifically targeting Claude Code users and developers. Related incidents include trojanized Zoom installers attributed to Iran-linked Nimbus Manticore used against US firms, and a ClickFix macOS infostealer compromise of a retail site. Overall activity leverages SEO poisoning, trojanized installers, and fileless techniques to harvest credentials and developer secrets, increasing risk to AI-tool

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
83e6ec0e60caf32015d1cdbc3d593557c9bad34c5b27ba09b45d9067064cf4bf
Enrichment time
2026-05-30T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users · Baitaphish