Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning
2026-05-22T14:52:16Z•d93feb93f91a8db3bd7131a6a16fbe4d82215884fcf81c9af4764e24dc106faa
agentic-aiai-securityandroid-malwareavada-builderexchange-zero-dayfragnesiagithub-breachgrafanagremlin-stealerinfostealerlinux-kernel-flawmalicious-extensionnpm-compromisepremium-fraudptraceransomware-enablerssbomseo-poisoningsource-code-theftsupply-chaintanstackvpn-takedownvs-code-extensionwordpress
What happened
Multiple high-impact supply‑chain incidents, active malware campaigns and critical vulnerabilities were reported. SEO‑poisoning campaigns used fake Gemini/Claude code sites to distribute infostealers that harvest credentials, crypto wallets and authentication keys; modular Gremlin stealer and a large Android premium‑billing fraud campaign remain active. Significant supply‑chain compromises and code theft include a malicious 'Nx Console' VS Code extension tied to a GitHub breach and stolen source code (Grafana/TanStack), Mini Shai‑Hulud infections across TanStack npm packages and PyPI, and Avda
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- d93feb93f91a8db3bd7131a6a16fbe4d82215884fcf81c9af4764e24dc106faa
- Enrichment time
- 2026-05-22T14:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.